Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
utils/scanpypi: protect against zip-slip vulnerability in zip/tar han…
…dling For details, see https://github.com/snyk/zip-slip-vulnerability Older python versions do not validate that the extracted files are inside the target directory. Detect and error out on evil paths before extracting .zip / .tar file. Given the scope of this (zip issue was fixed in python 2.7.4, released 2013-04-06, scanpypi is only used by a developer when adding a new python package), the security impact is fairly minimal, but it is good to get it fixed anyway. Reported-by: Bas van Schaik <[email protected]> Signed-off-by: Peter Korsgaard <[email protected]>
- Loading branch information