summaryrefslogtreecommitdiff
path: root/Mailman/Cgi/create.py
diff options
context:
space:
mode:
authorbwarsaw2001-11-20 16:25:51 +0000
committerbwarsaw2001-11-20 16:25:51 +0000
commit8f5694e541419427bcf6bcad383659c28fdbbeb1 (patch)
tree18c19a2f4a5eb8c50cfa59266167a748752591bd /Mailman/Cgi/create.py
parentdea54ee3cbcaa33bd3f9384cbfa08a4c3657b483 (diff)
downloadmailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.tar.gz
mailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.tar.zst
mailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.zip
CheckCookie(): Let's be explicit about using the Cookie.SimpleCookie
class to decode the cookie data so there's no possibility of unpickling exploits of untrusted data. I'm still mildly concerned about using marshal.loads() to de-serialize the cookie data we want to use for authorization, although I think we're more or less safe for the reasons described in the preceding comment. I should probably think about this some more, possibly using the newly documented pickle anti-exploit measures.
Diffstat (limited to 'Mailman/Cgi/create.py')
0 files changed, 0 insertions, 0 deletions