When extracting, skip ".." members
* NEWS: Document this. * src/extract.c (extract_archive): Skip members whose names contain "..".
This commit is contained in:
8
NEWS
8
NEWS
@@ -1,9 +1,15 @@
|
||||
GNU tar NEWS - User visible changes. 2016-05-27
|
||||
GNU tar NEWS - User visible changes. 2016-10-29
|
||||
Please send GNU tar bug reports to <bug-tar@gnu.org>
|
||||
|
||||
|
||||
version 1.29.90 (Git)
|
||||
|
||||
* Member names containing '..' components are now skipped when extracting.
|
||||
|
||||
This fixes tar's behavior to match its documentation, and is a bit
|
||||
safer when extracting untrusted archives over old files (an unsafe
|
||||
practice that the tar manual has long recommended against).
|
||||
|
||||
* Report erroneous use of positional options.
|
||||
|
||||
During archive creation or update, tar keeps track of positional
|
||||
|
||||
Reference in New Issue
Block a user