Page MenuHomePhabricator

1.31.0 tarball is missing .htaccess files (CVE-2018-13258)
Closed, ResolvedPublic


The .htaccess files are used to protect some directories that shouldn't be web accessible.

I believe it was rMREL41c86dd3eb87: make-release: Simplify excludes, just drop all .dotfiles that caused this.

Event Timeline

The patch is really simple obviously. I'm still working on the new release script (T199467) though to actually use gitattributes.

Legoktm added a subscriber: Jjjjjjjjjj.

Has this been included in your bundled patches for the branches? Or is this still in addition to T181665#4552739 ?

Just to make sure it doesn't accidentally get forgotten about :)

Has this been included in your bundled patches for the branches? Or is this still in addition to T181665#4552739 ?

Just to make sure it doesn't accidentally get forgotten about :)

It should be included in each of the patch tars :) It does require using the new release script though, since that uses .gitattributes when deciding what to exclude. If we don't end up using it, we'll need to figure out a different solution for this bug (that said, I'd rather invest in fixing the new release script :))

Reedy assigned this task to Legoktm.
Reedy changed the visibility from "Custom Policy" to "Public (No Login Required)".Sep 20 2018, 9:35 PM
MoritzMuehlenhoff renamed this task from 1.31.0 tarball is missing .htaccess files to 1.31.0 tarball is missing .htaccess files (CVE-2018-13258).Sep 21 2018, 7:26 AM