Message93251
Do people have an opinion as to whether this should be fixed with a
docfix, fixed as default (with option to allow path traversal) or fixed as
a non-default option? The same issue exists in ZipFile.extract, but in
that case you're presumably passing a path you've already vetted.
Either way, I'll write a test case for it tomorrow. |
|
| Date |
User |
Action |
Args |
| 2009-09-29 04:19:38 | twb | set | recipients:
+ twb, schmir |
| 2009-09-29 04:19:38 | twb | set | messageid: <[email protected]> |
| 2009-09-29 04:19:37 | twb | link | issue6972 messages |
| 2009-09-29 04:19:36 | twb | create | |
|