bagder: curl-www curl-content-disposition.patch,NONE,1.1

[email protected] Wed, 15 Dec 2010 22:12:29 +0000
Newsgroups gmane.comp.web.curl.www.cvs
Message-ID <[email protected]>
Update of /cvsroot/curl/curl-www
In directory giant.haxx.se:/var/tmp/cvs-serv18083

Added Files:
	curl-content-disposition.patch 
Log Message:
commit the patch


--- NEW FILE: curl-content-disposition.patch ---
commit 83ae6a0cecfd9c420e1fe153daf5be4e044b0929
Author: Daniel Stenberg <[email protected]>
Date:   Thu Sep 16 23:11:48 2010 +0200

    header_callback: strip off file path separated with backslashes
    
    If the filename contains a backslash, only use filename portion. The
    idea is that even systems that don't handle backslashes as path
    separators probably want that path removed for convenience.
    
    This flaw is considered a security problem, see the curl security
    vulnerability http://curl.haxx.se/docs/adv_20101013.html

diff --git a/src/main.c b/src/main.c
index 8572328..95b47ea 100644
--- a/src/main.c
+++ b/src/main.c
@@ -4368,6 +4368,18 @@ parse_filename(char *ptr, size_t len)
     }
   }
 
+  /* If the filename contains a backslash, only use filename portion. The idea
+     is that even systems that don't handle backslashes as path separators
+     probably want the path removed for convenience. */
+  q = strrchr(p, '\\');
+  if (q) {
+    p = q+1;
+    if (!*p) {
+      free(copy);
+      return NULL;
+    }
+  }
+
   if(quote) {
     /* if the file name started with a quote, then scan for the end quote and
        stop there */