>> So yes, it was clearly intentional; and it looks like it should also be 
>> handling quotes properly. Can you send me a config file that's being 
>> improperly parsed?
> 
> We could but it would make little sense to you since the requirement for 
> the parsing of quoted strings is a result of local patch.  We define a 
> number of error text strings in the config file, which allow us to 
> change and tailor the errors on the cgi output without recompiling the 
> cgi. With the change of that flag from 3.0.0 source it was parsing the 
> strings only up to the first space. Setting the default flags to 2 (or 
> 3) resolves the problem. We were just wondering why the default flags 
> had been changed between releases in case we were re-introducing a 
> vulnerability.

Okay. If any of it is still unclear for you, let me know and I can dig further.

Let me ask another question, though: would you be willing to share your code / 
implementation methodology so that we can document it for others that might 
benefit from the same approach?

-- Jorj


------------------------------------------------------------------------------
Dive into the World of Parallel Programming. The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Cosign-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/cosign-discuss

Reply via email to