From kde-commits Mon Jan 10 17:33:35 2011 From: Dawit Alemayehu Date: Mon, 10 Jan 2011 17:33:35 +0000 To: kde-commits Subject: KDE/kdelibs/kioslave/http Message-Id: <20110110173335.0F026AC8B2 () svn ! kde ! org> X-MARC-Message: https://marc.info/?l=kde-commits&m=129468085721866 SVN commit 1213508 by adawit: Don't allow control characters even in quoted file names. M +2 -0 parsinghelpers.cpp --- trunk/KDE/kdelibs/kioslave/http/parsinghelpers.cpp #1213507:1213508 @@ -374,6 +374,8 @@ ++pos; endquote = true; break; + } else if (!str[pos].isPrint()) { // Don't allow CTL's RFC 2616 sec 2.2 + break; } else { out += str[pos]; ++pos;