bug-tar
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Bug-tar] GNUTYPE_NAMES dangerous


From: Kees Cook
Subject: [Bug-tar] GNUTYPE_NAMES dangerous
Date: Fri, 24 Nov 2006 11:40:06 -0800

Hello!

Due to a full-disclosure email, I opened the following bug in savanah: 
https://savannah.gnu.org/bugs/index.php?18355

I proposed a patch there to disable GNUTYPE_NAMES handling by default, 
adding an option "--allow-name-mangling" to re-enable it.  Since 
GNUTYPE_NAMES can't be created by tar any more, and it doesn't seem 
designed to allow for symlink creation delay, this seemed like a 
sensible solution.  

Thoughts on this?

Thanks!

-- 
Kees Cook




reply via email to

[Prev in Thread] Current Thread [Next in Thread]