aboutsummaryrefslogtreecommitdiffstatshomepage
path: root/cgi.h.example
diff options
context:
space:
mode:
authorIngo Schwarze <schwarze@openbsd.org>2014-07-19 13:15:11 +0000
committerIngo Schwarze <schwarze@openbsd.org>2014-07-19 13:15:11 +0000
commitae6641bfafe5f6d5cefa0d535c66b5cfd989f218 (patch)
treef66ae90e4f25e6022d47e2fd04882be9786dc905 /cgi.h.example
parent52307465eda0160606943b97a728c54484b26fd7 (diff)
downloadmandoc-ae6641bfafe5f6d5cefa0d535c66b5cfd989f218.tar.gz
mandoc-ae6641bfafe5f6d5cefa0d535c66b5cfd989f218.tar.zst
mandoc-ae6641bfafe5f6d5cefa0d535c66b5cfd989f218.zip
Security fix:
Validate the manpath up front and report a Bad Request if it is not listed in manpath.conf, such that clients can't probe which directories exist on the server. In case of configuration errors, consistently report Internal Server Error without disclosing any further information. Partially based on a patch from Sebastien Marie <semarie-openbsd at latrappe dot fr>, but avoiding a couple of issues with that patch and approaching the issue in a somewhat more rigorous way.
Diffstat (limited to 'cgi.h.example')
0 files changed, 0 insertions, 0 deletions