The patch is released by upstream and is a simple sanity check with regex to remove leading '/' from an open(). It was built and tested that the patch applies succesfully.
https://bugzilla.mozilla.org/show_bug.cgi?id=437169 are details and the patch. -- [CVE-2008-4437] - Directory traversal vulnerability allows remote attackers to read arbitrary files via an XML file https://bugs.launchpad.net/bugs/281915 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
