Please sign in to comment.
Prohibit file injection writing to host filesystem
This is a refinement of the previous fix in commit 2427d4a, which does the file name canonicalization as the root user. This is required so that guest images could not for example, protect malicious symlinks in a directory only readable by root. Fixes bug: 1031311, CVE-2012-3447 Change-Id: I7f7cdeeffadebae7451e1e13f73f1313a7df9c5c
- Loading branch information...
Showing with 36 additions and 17 deletions.