Bug#332411: CAN-2005-3163: polipo permits reading files outside of web root dir

2006-01-16 Thread Juliusz Chroboczek
I am the upstream author, and I can confirm this issue. However, please keep in mind that Polipo is also vulnerable (by design) to a number of DoS attacks from users. Allowing Polipo to be used by untrusted users is not recommended in any case. Juliusz

Bug#332411: CAN-2005-3163: polipo permits reading files outside of web root dir

2005-10-06 Thread Moritz Muehlenhoff
Package: polipo Severity: important Tags: security polipo 0.9.9 fixes an unspecified security problem that permits attackers to read files outside of the web root directory. Please mention the CVE assignment (CAN-2005-3163) when fixing this issue. Cheers, Moritz -- System Information: