bug-tar
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Bug-tar] Unexpected symlink attack due to change in link following


From: Sergey Poznyakoff
Subject: Re: [Bug-tar] Unexpected symlink attack due to change in link following behaviour
Date: Mon, 12 Sep 2005 13:28:32 +0300

Clarence Dang <address@hidden> wrote:

> I just discovered that tar 1.14 enabled the opposite of "--no-overwrite-dir" 
> by default.  This is an unexpected and subtle change in behavior.

The change in question was mage on 2001-09-24 in order to make the
default GNU tar behavior compatible with that of another existing tar
implementations.

It was discussed on the list and is explicitely documented in NEWS file.

Regards,
Sergey
 




reply via email to

[Prev in Thread] Current Thread [Next in Thread]