Subject: | Archive::Tar cannot handle extracted files securely |
Date: | Thu, 20 Sep 2007 19:59:11 +0200 |
To: | bug-archive-tar [...] rt.cpan.org |
From: | Anicka Bernathova <anicka [...] suse.cz> |
Hello,
this is a feature request more than a bugreport:
Archive::Tar does not take any care for controlling whether the
extracted files leave the current directory or not. It is willing to try
to rewrite any files in the system by extracting archived files with
absolute paths, following any archived symlinks and so on.
This is usually considered a security problem and ie. GNU tar has many
fixes to avoid this behavior. Are you willing to add some switch to
enable a secure way of handling the extracted files in Archive::Tar too?
I will gladly help with implementation, if you find it worth of doing.
Thanks!
--
Best Regards,
Anna Bernathova, software developer
---------------------------------------------------------------------
SUSE LINUX, s.r.o. e-mail: anicka@suse.cz
Lihovarska 1060/12 tel: +420 2 9654 2375
190 00 Praha 9 fax: +420 2 8309 5374
Czech Republic http://www.suse.cz