diff options
| author | bwarsaw | 2001-11-20 16:25:51 +0000 |
|---|---|---|
| committer | bwarsaw | 2001-11-20 16:25:51 +0000 |
| commit | 8f5694e541419427bcf6bcad383659c28fdbbeb1 (patch) | |
| tree | 18c19a2f4a5eb8c50cfa59266167a748752591bd /Mailman/Cgi/create.py | |
| parent | dea54ee3cbcaa33bd3f9384cbfa08a4c3657b483 (diff) | |
| download | mailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.tar.gz mailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.tar.zst mailman-8f5694e541419427bcf6bcad383659c28fdbbeb1.zip | |
CheckCookie(): Let's be explicit about using the Cookie.SimpleCookie
class to decode the cookie data so there's no possibility of
unpickling exploits of untrusted data.
I'm still mildly concerned about using marshal.loads() to de-serialize
the cookie data we want to use for authorization, although I think
we're more or less safe for the reasons described in the preceding
comment. I should probably think about this some more, possibly using
the newly documented pickle anti-exploit measures.
Diffstat (limited to 'Mailman/Cgi/create.py')
0 files changed, 0 insertions, 0 deletions
