Re: fetch extension - use local filename from content-disposition header
- From: Pawel Worach <pawel.worach@xxxxxxxxx>
- Date: Fri, 30 Dec 2005 03:27:46 +0100
Sean Bryant wrote:
Barney Wolff wrote:
On Thu, Dec 29, 2005 at 07:33:38PM -0500, Martin Cracauer wrote:Its just an extra option. I'm sure the details could be summed up in the man page.
I'm a bit rusty, so please point me to style mistakes in the appended
diff.
The following diff implements a "-O" option to fetch(1), which, when
set, will make fetch use a local filename supplied by the server in a
Content-Disposition header.
Have you considered the security implications of this option?
I think what Barney means is that if you run fetch(1) as root and the server returns the filename as "/sbin/init" bad things will happen.
The data returned in Content-Disposition should be used with caution.
-- Pawel _______________________________________________ freebsd-current@xxxxxxxxxxx mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-current To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: fetch extension - use local filename from content-disposition header
- From: Matt Emmerton
- Re: fetch extension - use local filename from content-disposition header
- From: Martin Cracauer
- Re: fetch extension - use local filename from content-disposition header
- References:
- fetch extension - use local filename from content-disposition header
- From: Martin Cracauer
- Re: fetch extension - use local filename from content-disposition header
- From: Barney Wolff
- Re: fetch extension - use local filename from content-disposition header
- From: Sean Bryant
- fetch extension - use local filename from content-disposition header
- Prev by Date: Re: fetch extension - use local filename from content-disposition header
- Next by Date: Re: fetch extension - use local filename from content-disposition header
- Previous by thread: Re: fetch extension - use local filename from content-disposition header
- Next by thread: Re: fetch extension - use local filename from content-disposition header
- Index(es):
Relevant Pages
|
|