Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20250620210452.F39EF41C@notatla.org.uk>
Date: Fri, 20 Jun 2025 22:04:52 +0100
From: lists@...atla.org.uk
To: oss-security@...ts.openwall.com
Subject: Re: path traversal in tar extract in intel
 cve-bin-tool

> But the custom filter wouldn't be sound even with the typo fixed, 
> because str.startswith() and Path.resolve() are wrong tools for the job.

> Anyway, I suspect that cve-bin-tool's extractors for other file formats 
> are still vulnerable to path traversal, so I wouldn't recommend running 
> it against untrusted files.


`We must first agree that software security is not security
software', writes Gary McGraw in the first chapter ..


http://swsec.com/press/ra-ieeesp.php

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.