Bug#304712: avaMail allows directory traversal in attachments (CAN-2005-1105)

Javier Serrano Polo jasp00 at terra.es
Tue Apr 24 21:16:56 UTC 2007


El dt 24 de 04 del 2007 a les 19:17 +0200, en/na Florian Weimer va
escriure:
> I guess the documentation shoud be clarified:

I don't know where that text came from (it's in a previous link, I
know). From:

http://java.sun.com/j2ee/1.4/docs/api/javax/mail/internet/MimeBodyPart.html#getFileName()

        Get the filename associated with this body part. 
        
        Returns the value of the "filename" parameter from the
        "Content-Disposition" header field of this body part. If its not
        available, returns the value of the "name" parameter from the
        "Content-Type" header field of this body part. Returns null if
        both are absent.

Pretty clear, isn't it?





More information about the pkg-java-maintainers mailing list