10f15e6669
Compression filter named in a backup header is executed in restore environment (commonly dom0). While this field is properly authenticated, there may be cases where backup archive comes from less trusted source, like migrating from potentially compromised system. Modify backup header parsing code to add field specific validators. Whitelist only know crypto, hmac and compression algorithms. Based on a patch by Jean-Philippe Ouellet <jpo@vt.edu> Reported-by: Jean-Philippe Ouellet <jpo@vt.edu> |
||
---|---|---|
.. | ||
backup | ||
events | ||
tests | ||
tools | ||
vm | ||
__init__.py | ||
app.py | ||
base.py | ||
config.py | ||
devices.py | ||
exc.py | ||
features.py | ||
firewall.py | ||
label.py | ||
log.py | ||
qubesadmin | ||
spinner.py | ||
storage.py | ||
tags.py | ||
utils.py |