Mojira Archive
MCPE-8124

MCPE does not check world names for impermissible characters

I created a world with the name "../" without the quotes.

what happened: The world files were saved under /mnt/games/com.mojang/

what I expected to happen: the world filed would be saved under /mnt/games/com.mojang/minecraftWorlds/SOMETHING where SOMETHING is some folder name used when you name your world something that uses impermissible file name characters.

This bug does not appear to be a security flaw/risk because MCPE gives a "can't open world" if you try to make a world that writes to a place you can't access.

Also, after quiting to the menu, this world will never appear in the world list because it's not in the right folder.

Device is Samsung Galaxy S4 android 4.4.2 running MCPE 0.10.5.

Attachments1

Comments4

Not sure if file system bugs go to Shoghi or Daniel, so I flipped a coin. Congrats Shoghi

Hi Russell, this issue does not occur using 0.10.4 on an iPhone 6 plus running iOS 8.2. Attempting to use the "/" character does not result in it being entered into the world name.

What is the chance your gonna name your world ../?

I named a world " .. " without the quotes, and it indeed didn't show up in my world list.

History6

rplatham

Added attachment:

Changed description:

I created a world with the name "../" without the quotes.

0

what happened: The world files were saved under /mnt/games/com.mojang/

0

what I expected to happen: the world filed would be saved under /mnt/games/com.mojang/minecraftWorlds/SOMETHING where SOMETHING is some folder name used when you name your world something that uses impermissible file name characters.

0

I am concerned that this bug could be a security flaw/risk as it may allow users to write files to locations the user should not be able to write to.

0

Also, after quiting to the menu, this world will never appear in the world list because it's not in the right folder.

0

Device is Samsung Galaxy S4 android 4.4.2 running MCPE 0.10.5.

I created a world with the name "../" without the quotes.

0

what happened: The world files were saved under /mnt/games/com.mojang/

0

what I expected to happen: the world filed would be saved under /mnt/games/com.mojang/minecraftWorlds/SOMETHING where SOMETHING is some folder name used when you name your world something that uses impermissible file name characters.

0

This bug does not appear to be a security flaw/risk because MCPE gives a "can't open world" if you try to make a world that writes to a place you can't access.

0

Also, after quiting to the menu, this world will never appear in the world list because it's not in the right folder.

0

Device is Samsung Galaxy S4 android 4.4.2 running MCPE 0.10.5.

Added labels: Files Folders Saving

Removed labels:

rplatham
[Mojang] Shoghi Cervantes

Resolution: UnresolvedFixed

Added affects versions: 0.11.0

Deleted account

Added labels: files saving folders

Removed labels: Files Folders Saving

Fixed
rplatham
0
2
Unconfirmed
files folders saving
0.10.5
0.11.0