bug-cpio
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Regression in handling of CVE-2015-1197 & --no-absolute-filenames br


From: Mike Gilbert
Subject: Re: Regression in handling of CVE-2015-1197 & --no-absolute-filenames breaks symlinks starting with /
Date: Wed, 8 Jan 2020 11:11:58 -0500

On Wed, Jan 8, 2020 at 9:38 AM Chris Lamb <address@hidden> wrote:
>
> [please retain any CCs when replying; I am not subscribed to the list]
>
> Dear cpio maintainers,
>
> (I am not the Maintainer of cpio in Debian so was not alerted to the
> issue until recently, but was asked to look into this.)
>
> The following bug was filed in Debian:
>
>   https://bugs.debian.org/946267
>
> … which reports a recent regression in cpio whereby --no-absolute-
> filenames breaks the extraction of symlinks starting with /.

I reported a similar issue in November, and I don't think it has been fixed yet.

https://lists.gnu.org/archive/html/bug-cpio/2019-11/msg00013.html



reply via email to

[Prev in Thread] Current Thread [Next in Thread]