https://bugzilla.redhat.com/show_bug.cgi?id=1588760


--- Doc Text *updated* by Eric Christensen <spa...@redhat.com> ---
It was found that the Archive::Tar module did not properly sanitize symbolic 
links when extracting tar archives. An attacker, able to provide a specially 
crafted archive for processing, could use this flaw to write or overwrite 
arbitrary files in the context of the Perl interpreter.


-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org/message/AKFH7JVM7SOPGNYLTCPY54ELX6EKWWY2/

Reply via email to