Salut, On Wed, 2006-09-20 at 13:37 -0700, Jon Hart wrote: > Think of some of the risks here. tar archives that unpack into . or > ../../../some/sensitive/dir The former is plain evil but can be avoided, the latter is usually extracted to ./some/sensitive/dir. Anything else would be a usual directory traversal vulnerability. Yes, they also exist, but if so, it needs to be fixed inside your tar program. NetBSD and Solaris tar for example don't seem to have this vulnerability. Nor does the dreaded GNU tar. Tonnerre -- SyGroup GmbH Tonnerre Lombard Loesungen mit System Tel:+41 61 333 80 33 Roeschenzerstrasse 9 Fax:+41 61 383 14 67 4153 Reinach BL Web:www.sygroup.ch tonnerre.lombard@xxxxxxxxxx
Attachment:
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/