Taking a quick glance at the source of the project in question, I suspect there is no intention to attempt to restrict which files may be accessed beyond controls enforced by the operating system access controls:
http://sources.debian.net/src/simple- xml/2.7.1-1/src/org/simpleframework/xml/transform/FileTransform.java/?hl=2#L57 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1406411 Title: BUG - External Control of File Name or Path - FileTransform.java To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/simple-xml/+bug/1406411/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
