[issue21109] tarfile: Traversal attack vulnerability

Daniel Garcia report at bugs.python.org
Mon Mar 31 10:23:03 CEST 2014


Daniel Garcia added the comment:

The solution in the patch is based on the gnutar solution to this, removing the prefix when extracting and adding.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue21109>
_______________________________________


More information about the Python-bugs-list mailing list