New issue
Advanced search Search tips

Issue 638649 link

Starred by 0 users

Issue metadata

Status: Archived
Owner: ----
Closed: Jan 10
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Unescaped command string formatting/shell injection

Project Member Reported by ayatane@chromium.org, Aug 17 2016

Issue description

There are calls to host.run() that format command strings naively, potentially vulnerable to injection or bugs.

Example in autotest server/crashcollect.py
 
Labels: Hotlist-Fixit
Owner: ----
Status: Archived (was: Untriaged)
Archiving P3s older than 1 year with no owner or component.

Sign in to add a comment