Home page logo

oss-sec logo oss-sec mailing list archives

Re: Geany IDE not escaping filenames during compilation / build - a security issue or not?
From: Eitan Adler <lists () eitanadler com>
Date: Thu, 13 Dec 2012 00:54:12 -0500

On 12 December 2012 11:51, Jan Lieskovsky <jlieskov () redhat com> wrote:
The questions:
1) should Geany escape the filenames?,

Up to the maintainers.

2) is this a security issue or not?

Unlikely.  Is there a way a malicious document could cause code
execution without user action?

Eitan Adler

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]