[Bug 1636207] Re: Patch proposal to do not apply symbolic links included in zip files.

Ubuntu Foundations Team Bug Bot 1636207 at bugs.launchpad.net
Tue Oct 25 12:36:26 UTC 2016


The attachment "do_not_apply_symlinks.patch" seems to be a patch.  If it
isn't, please remove the "patch" flag from the attachment, remove the
"patch" tag, and if you are a member of the ~ubuntu-reviewers,
unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by
~brian-murray, for any issues please contact him.]

** Tags added: patch

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to unzip in Ubuntu.
https://bugs.launchpad.net/bugs/1636207

Title:
  Patch proposal to do not apply symbolic links included in zip files.

Status in unzip package in Ubuntu:
  New

Bug description:
  Zip files might include symbolic links which could be abused by an
  attacker to escape from restricted directories and/or from restricted
  environments. The attached patch includes a command line option -g
  which does not apply the symbolic links when zip file is extracted. In
  case a zip file includes a symbolic link a file is created instead
  containing the target of the symbolic link.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1636207/+subscriptions



More information about the foundations-bugs mailing list