Comment 1 for bug 1410839

Revision history for this message
costales (costales) wrote : Re: [Bug 1410839] [NEW] Shell Command injection in ufw_backend.py

Hi! Thanks a lot for your feedback!

The user only can to create profiles with letters, numbers, dashes and
underscores.
http://bazaar.launchpad.net/~costales/gui-ufw/gufw-15.04/view/head:/gufw/view/preferences.py#L101
<http://bazaar.launchpad.net/%7Ecostales/gui-ufw/gufw-15.04/view/head:/gufw/view/preferences.py#L101>
A profile with semicolons will be reject.

I was thinking about to filter in the ufw_backend.py in any way?
Best regards!