|
|
|
|
|
by technion
1087 days ago
|
|
OK hear me out: a Linux capability like option that removes the .. option from the kernels file name parser. Like web apps have been seen various bypasses involving somehow smuggling two dots somewhere since we were on dial up modems. It's time to look for a way to close this once and for all, as the Linux kernel has done with several other classes of user land bugs. |
|
(FreeBSD has this in ordinary openat(2) as O_RESOLVE_BENEATH.)