Refuse to open a msglog file with .. in the path.
authorJeremy Harris <jgh146exb@wizmail.org>
Tue, 10 Sep 2019 11:29:12 +0000 (12:29 +0100)
committerJeremy Harris <jgh146exb@wizmail.org>
Tue, 10 Sep 2019 11:33:28 +0000 (12:33 +0100)
Recent exploits have use this as a step for overwriting system files,
and msglog file should always be under the spooldir, so add this as
a defence-in-depth tactic


No differences found