This repository was archived by the owner on Oct 30, 2018. It is now read-only.
Commit 7c3999a
do not use a predictable filenames in the LXC plugin
* do not use a predictable filename for the LXC attach script
* don't use predictable filenames for LXC attach script logging
* don't set a predictable archive_path
this should prevent symlink attacks which could result in
* data corruption
* data leakage
* privilege escalation1 parent f710908 commit 7c3999a
1 file changed
Lines changed: 8 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
144 | 144 | | |
145 | 145 | | |
146 | 146 | | |
147 | | - | |
| 147 | + | |
148 | 148 | | |
149 | 149 | | |
150 | 150 | | |
| |||
557 | 557 | | |
558 | 558 | | |
559 | 559 | | |
560 | | - | |
561 | | - | |
562 | | - | |
563 | | - | |
564 | | - | |
565 | | - | |
566 | | - | |
| 560 | + | |
| 561 | + | |
567 | 562 | | |
568 | 563 | | |
569 | 564 | | |
| |||
573 | 568 | | |
574 | 569 | | |
575 | 570 | | |
576 | | - | |
577 | | - | |
578 | | - | |
579 | 571 | | |
580 | | - | |
| 572 | + | |
581 | 573 | | |
582 | 574 | | |
583 | | - | |
| 575 | + | |
584 | 576 | | |
585 | 577 | | |
586 | 578 | | |
| |||
1747 | 1739 | | |
1748 | 1740 | | |
1749 | 1741 | | |
1750 | | - | |
1751 | 1742 | | |
1752 | 1743 | | |
1753 | 1744 | | |
1754 | 1745 | | |
1755 | 1746 | | |
1756 | 1747 | | |
1757 | 1748 | | |
| 1749 | + | |
| 1750 | + | |
| 1751 | + | |
1758 | 1752 | | |
1759 | 1753 | | |
1760 | 1754 | | |
| |||
0 commit comments