[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Regression in handling of CVE-2015-1197 & --no-absolute-filenames br

From: Mike Gilbert
Subject: Re: Regression in handling of CVE-2015-1197 & --no-absolute-filenames breaks symlinks starting with /
Date: Wed, 8 Jan 2020 11:11:58 -0500

On Wed, Jan 8, 2020 at 9:38 AM Chris Lamb <address@hidden> wrote:
> [please retain any CCs when replying; I am not subscribed to the list]
> Dear cpio maintainers,
> (I am not the Maintainer of cpio in Debian so was not alerted to the
> issue until recently, but was asked to look into this.)
> The following bug was filed in Debian:
>   https://bugs.debian.org/946267
> … which reports a recent regression in cpio whereby --no-absolute-
> filenames breaks the extraction of symlinks starting with /.

I reported a similar issue in November, and I don't think it has been fixed yet.


reply via email to

[Prev in Thread] Current Thread [Next in Thread]