- Notifications
You must be signed in to change notification settings - Fork5
Commit3bf822c
committed
Disable the undocumented xmlvalidate() function, which was unintentionally
left in the code though it was not meant to be provided. It represents asecurity hole because unprivileged users could use it to look at (at least thefirst line of) any file readable by the backend. Fortunately, this is onlypossible if the backend was built with XML support, so the damage is at leastmitigated; and 8.3 probably hasn't propagated into any security-critical usesyet anyway. Per report from Sergey Burladyan.1 parent64f30bb commit3bf822c
1 file changed
+9
-60
lines changedLines changed: 9 additions & 60 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| |||
788 | 788 |
| |
789 | 789 |
| |
790 | 790 |
| |
791 |
| - | |
792 |
| - | |
793 |
| - | |
| 791 | + | |
| 792 | + | |
| 793 | + | |
| 794 | + | |
| 795 | + | |
794 | 796 |
| |
795 | 797 |
| |
796 | 798 |
| |
797 | 799 |
| |
798 |
| - | |
799 |
| - | |
800 |
| - | |
801 |
| - | |
802 |
| - | |
803 |
| - | |
804 |
| - | |
805 |
| - | |
806 |
| - | |
807 |
| - | |
808 |
| - | |
809 |
| - | |
810 |
| - | |
811 |
| - | |
812 |
| - | |
813 |
| - | |
814 |
| - | |
815 |
| - | |
816 |
| - | |
817 |
| - | |
818 |
| - | |
819 |
| - | |
820 |
| - | |
821 |
| - | |
822 |
| - | |
823 |
| - | |
824 |
| - | |
825 |
| - | |
826 |
| - | |
827 |
| - | |
828 |
| - | |
829 |
| - | |
830 |
| - | |
831 |
| - | |
832 |
| - | |
833 |
| - | |
834 |
| - | |
835 |
| - | |
836 |
| - | |
837 |
| - | |
838 |
| - | |
839 |
| - | |
840 |
| - | |
841 |
| - | |
842 |
| - | |
843 |
| - | |
844 |
| - | |
845 |
| - | |
846 |
| - | |
847 |
| - | |
848 |
| - | |
849 |
| - | |
850 |
| - | |
851 |
| - | |
852 |
| - | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
853 | 803 |
| |
854 |
| - | |
855 | 804 |
| |
856 | 805 |
| |
857 | 806 |
| |
|
0 commit comments
Comments
(0)