Message157778
| Author |
serhiy.storchaka |
| Recipients |
amaury.forgeotdarc, gregory.p.smith, ned.deily, r.david.murray, schmir, serhiy.storchaka, twb |
| Date |
2012年04月08日.06:56:47 |
| SpamBayes Score |
-1.0 |
| Marked as misclassified |
Yes |
| Message-id |
<1333868208.35.0.161512154373.issue6972@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
> + # make sure the zip file isn't traversing out of the path
> + if not targetpath.startswith(basepath):
Check is insufficient. basepath='/etc/asd', member.filename='../asdfgh'.
The issue10905 has relations with this issue.
P. S. Viewing patches in this issue is not working. |
|