[flashrom] flashrom accepts its command line parameters as a file name to read to

Idwer Vollering vidwer at gmail.com
Thu Aug 18 17:57:59 CEST 2011


2011/8/18 Christophe Poncy <cp at canaxis.org>:
> Hi,
>

...

> # ./flashrom -r -L

This shouldn't be allowed.

What about disallowing the creation of files that have a name listed
in cli_classic.c's optstring[] and/or long_options[] ?

What's funny (or not..) is that running "flashrom -r -r" is allowed as well.




More information about the flashrom mailing list