[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Bug-tar] tar-1.13.92 strips leading or contained './'
From: |
Martin Schlemmer |
Subject: |
Re: [Bug-tar] tar-1.13.92 strips leading or contained './' |
Date: |
Tue, 06 Jan 2004 23:30:29 +0200 |
On Tue, 2004-01-06 at 23:21, Sergey Poznyakoff wrote:
> > As above. Having a path start with './' or containing '/./' is not
> > a security risk, and even used by some archiving apps as security
> > measure (like unzip that appends './'). This behaviour breaks reacent
> > tarballs (among those are tcpdump-3.8.1.tar.gz, and most ones in RH
> > src.rpm's).
>
> Yes, Martin, you are are right. I've already fixed this in the repository.
>
Proper fix, or do I miss somethings (would appreciate proper fix if
mine is not 100%).
Thanks,
--
Martin Schlemmer
signature.asc
Description: This is a digitally signed message part