Bugs item #1881599, was opened at 2008-01-28 21:33
Message generated for change (Tracker Item Submitted) made by Item Submitter
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=642714&aid=1881599&group_id=105970

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: build process
Group: v3.0
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: Krzysztof Wilkosz (kwilk)
Assigned to: Nobody/Anonymous (nobody)
Summary: Standard COM keys should be validated for quoting

Initial Comment:
Registry keys for COM written to 
HKCR\CLSID\{UUID-UUID-UUID}\LocalServer32
HKCR\CLSID\{UUID-UUID-UUID}\LocalServer
HKCR\CLSID\{UUID-UUID-UUID}\InprocServer32
HKCR\CLSID\{UUID-UUID-UUID}\InprocServer

should be checked for correct quoting (must be quoted). Leaving values of these 
registry keys unquoted opens security hole.


----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=642714&aid=1881599&group_id=105970

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
WiX-devs mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/wix-devs

Reply via email to