Dong-hee Na added the comment:

One of the purposes of the JDK patch is to prevent '\ r' and '\ n' from being 
inserted into the ftp command. In particular, it seems to assume that if 
another malice command is inserted after '\ n', the possibility of such an 
attack will be opened at a later time.
IMO, I think that we can block '\ r \ n' and '\ n' at the same time by blocking 
only '\ n'. Although '\ r' allows

----------

_______________________________________
Python tracker <rep...@bugs.python.org>
<http://bugs.python.org/issue30119>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to