Bug#842339: [Bug-tar] possible fixes for CVE-2016-6321

2016-10-30 Thread Salvatore Bonaccorso
Control: tags -1 + patch (dropping the bug-tar list, since this reply only relevant within Debian). Hi Paul, On Sat, Oct 29, 2016 at 09:19:09PM -0700, Paul Eggert wrote: > Thanks for the heads-up. Yes, it appears the 2003 change was not > sufficiently paranoid about ".." in member names. Luckily

Bug#842339: [Bug-tar] possible fixes for CVE-2016-6321

2016-10-29 Thread Paul Eggert
Thanks for the heads-up. Yes, it appears the 2003 change was not sufficiently paranoid about ".." in member names. Luckily, the tar manual still documents the pre-2003 behavior, so we can restore that behavior as a simple bug fix. I installed the attached patch into Savannah as one way to do tha