Re: Directory traversal vulnerabilities in several archivers processing .tar

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> [...how tarfile readers don't check for .. components...]

> Affected
> [long list]

Not affected: my tar, when run with the appropriate option to make it
paranoid about extraction.  (With the option set, it refuses to extract
anything that would be placed anywhere not under the current
directory.  At least it's supposed to, and as far as I know it does.)

/~\ The ASCII				der Mouse
\ / Ribbon Campaign
 X  Against HTML	       mouse@rodents.montreal.qc.ca
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux