summaryrefslogtreecommitdiff
path: root/RELEASE_NOTES.md
diff options
context:
space:
mode:
authorTomSweeneyRedHat <tsweeney@redhat.com>2021-02-27 19:53:03 -0500
committerMatthew Heon <mheon@redhat.com>2021-03-29 13:42:36 -0400
commit52cd3ce2d9e170d5c20246372cc1985d82b3533d (patch)
tree72b5de78bbc2e78b6a2f4e64284bcffe92649b4c /RELEASE_NOTES.md
parent633ae014e6945670676e4118356d09418c678138 (diff)
downloadpodman-52cd3ce2d9e170d5c20246372cc1985d82b3533d.tar.gz
podman-52cd3ce2d9e170d5c20246372cc1985d82b3533d.tar.bz2
podman-52cd3ce2d9e170d5c20246372cc1985d82b3533d.zip
Validate passed in timezone from tz option
Erik Sjolund reported an issue where a badly formated file could be passed into the `--tz` option and then the date in the container would be badly messed up: ``` erik@laptop:~$ echo Hello > file.txt erik@laptop:~$ podman run --tz=../../../home/erik/file.txt --rm -ti docker.io/library/alpine cat /etc/localtime Hello erik@laptop:~$ podman --version podman version 3.0.0-rc1 erik@laptop:~$ ``` This fix checks to make sure the TZ passed in is a valid value and then proceeds with the rest of the processing. This was first reported as a potential security issue, but it was thought not to be. However, I thought closing the hole sooner rather than later would be good. Signed-off-by: TomSweeneyRedHat <tsweeney@redhat.com>
Diffstat (limited to 'RELEASE_NOTES.md')
0 files changed, 0 insertions, 0 deletions