Skip to content

tarfile extract can write files outside the destination path #61304

@gpshead

Description

@gpshead
BPO 17102
Nosy @gpshead, @taleinat, @jwilk, @bitdancer, @serhiy-storchaka
Superseder
  • bpo-21109: tarfile: Traversal attack vulnerability
  • Files
  • absolute_path.tar: tar file with a single "/absolute_path" file in it.
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = <Date 2018-08-28.05:42:43.186>
    created_at = <Date 2013-02-02.06:02:27.626>
    labels = ['type-security', '3.7']
    title = 'tarfile extract can write files outside the destination path'
    updated_at = <Date 2018-08-28.05:42:43.185>
    user = 'https://github.com/gpshead'

    bugs.python.org fields:

    activity = <Date 2018-08-28.05:42:43.185>
    actor = 'gregory.p.smith'
    assignee = 'none'
    closed = True
    closed_date = <Date 2018-08-28.05:42:43.186>
    closer = 'gregory.p.smith'
    components = []
    creation = <Date 2013-02-02.06:02:27.626>
    creator = 'gregory.p.smith'
    dependencies = []
    files = ['28931']
    hgrepos = []
    issue_num = 17102
    keywords = []
    message_count = 4.0
    messages = ['181133', '181168', '181223', '324191']
    nosy_count = 7.0
    nosy_names = ['gregory.p.smith', 'taleinat', 'schmir', 'jwilk', 'Arfrever', 'r.david.murray', 'serhiy.storchaka']
    pr_nums = []
    priority = 'normal'
    resolution = 'duplicate'
    stage = 'resolved'
    status = 'closed'
    superseder = '21109'
    type = 'security'
    url = 'https://bugs.python.org/issue17102'
    versions = ['Python 2.7', 'Python 3.5', 'Python 3.6', 'Python 3.7']

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions