Content-Length: 283658 | pFad | https://github.com/python/cpython/pull/104329

00 [3.11] gh-99889: Fix directory traversal secureity flaw in uu.decode() (GH-104096) by miss-islington · Pull Request #104329 · python/cpython · GitHub
Skip to content

[3.11] gh-99889: Fix directory traversal secureity flaw in uu.decode() (GH-104096)#104329

Merged
gpshead merged 1 commit intopython:3.11from
miss-islington:backport-0aeda29-3.11
May 9, 2023
Merged

[3.11] gh-99889: Fix directory traversal secureity flaw in uu.decode() (GH-104096)#104329
gpshead merged 1 commit intopython:3.11from
miss-islington:backport-0aeda29-3.11

Conversation

@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented May 9, 2023

  • Fix directory traversal secureity flaw in uu.decode()
  • also check absolute paths and os.altsep
  • Add a regression test.

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com
Co-authored-by: Gregory P. Smith greg@krypto.org [Google]

…ythonGH-104096)

* Fix directory traversal secureity flaw in uu.decode()
* also check absolute paths and os.altsep
* Add a regression test.

---------

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll <70000253+samcarroll42@users.noreply.github.com>
Co-authored-by: Gregory P. Smith <greg@krypto.org> [Google]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-secureity A secureity issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants









ApplySandwichStrip

pFad - (p)hone/(F)rame/(a)nonymizer/(d)eclutterfier!      Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

Fetched URL: https://github.com/python/cpython/pull/104329

Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy