Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
mount.cifs: fix verbose messages on option parsing
When verbose logging is enabled, invalid credentials file lines may be dumped to stderr. This may lead to information disclosure in particular conditions when the credentials file given is sensitive and contains '=' signs. Bug: https://bugzilla.samba.org/show_bug.cgi?id=15026 Signed-off-by: Jeffrey Bencteux <jbe@improsec.com> Reviewed-by: David Disseldorp <ddiss@suse.de>
- Loading branch information
8acc963
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
CVE-2022-29869 is assigned for the issue fixed by this commit.
8acc963
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do you want me to put CVE-2022-29869 prefix to the title of the commit before pushing to git.samba.org, so it is more visible?
8acc963
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@piastry I guess it's not strictly needed, and would only do it if it does not cause issues with the commit history.
8acc963
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ok, will leave things as is to not cause conflicts to anyone who has already fetched the changes.