mirror of
https://github.com/f-droid/fdroidclient.git
synced 2026-06-20 13:49:47 -04:00
Apk.isMediaInstalled() needs to check using sanitized file names
The install process automatically sanitizes filenames to avoid exploits that put attack code in the filename. Media files are also installed using this logic, so the installed check needs to use sanitized file names to be accurate.
This commit is contained in:
committed by
Chirayu Desai
parent
c5a1b11315
commit
7dbf03c435
@@ -37,11 +37,11 @@ public class SanitizedFileTest {
|
||||
|
||||
assertEquals("/tmp/blah/safe", safeSanitized.getAbsolutePath());
|
||||
assertEquals("/tmp/blah/safe-and_bleh.boo", nonEvilSanitized.getAbsolutePath());
|
||||
assertEquals("/tmp/blah/rmetcshadow", evilSanitized.getAbsolutePath());
|
||||
assertEquals("/tmp/blah/rm etcshadow", evilSanitized.getAbsolutePath());
|
||||
|
||||
assertEquals("safe", safeSanitized.getName());
|
||||
assertEquals("safe-and_bleh.boo", nonEvilSanitized.getName());
|
||||
assertEquals("rmetcshadow", evilSanitized.getName());
|
||||
assertEquals("rm etcshadow", evilSanitized.getName());
|
||||
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user