Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve path traversal detection for forward and backward slashes #22

Merged
merged 1 commit into from
Jan 15, 2019
Merged

Improve path traversal detection for forward and backward slashes #22

merged 1 commit into from
Jan 15, 2019

Conversation

Ayesh
Copy link
Contributor

@Ayesh Ayesh commented Jan 11, 2019

Hallo Michiel,
I hope you remember our conversation with path traversal detection improvements. I thought to send a PR to see if it helps in any way.

In Windows, both forward and backward slashes are valid as directory separators, and because the Tar archive could come from different hosts, an archive packed with forward slashes would still work in Windows although we do not reject it.

This PR simplifies and blindly rejects path traversals in both systems. This aligns with GNU tar's detection.

@mrook mrook merged commit d1d112c into pear:master Jan 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants