Project

General

Profile

« Previous | Next » 

Revision fca16b0c

Added by shyouhei (Shyouhei Urabe) over 14 years ago

  • error.c (exc_to_s): untainted strings can be tainted via
    Exception#to_s, which enables attackers to overwrite sane strings.
    Reported by: Yusuke Endoh .

  • error.c (name_err_to_s): ditto.

  • test/ruby/test_exception.rb (TestException::test_to_s_taintness_propagation):
    Test for it.

git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/branches/ruby_1_8@30903 b2dd03c8-39d4-4d8f-98ff-823fe69b080e