From 0b507b17a760b21e33fc52ff377db6aa5086c680 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Wed, 3 Oct 2012 13:29:20 -0400 Subject: dbus: add some more safety checks before accepting data from bus clients --- src/journal/journald-native.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src/journal/journald-native.c') diff --git a/src/journal/journald-native.c b/src/journal/journald-native.c index 12fb980dd6..de8d6998cf 100644 --- a/src/journal/journald-native.c +++ b/src/journal/journald-native.c @@ -314,7 +314,7 @@ void server_process_native_file( return; } - if (strchr(e, '/')) { + if (!filename_is_safe(e)) { log_error("Received file in subdirectory of allowed directories. Refusing."); return; } -- cgit v1.2.3-54-g00ecf