Fix CVE-2007-4559 warnings in RHEL tar extraction. #62
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Basic Info
Description of contribution in a few bullet points
Added a basic safety check to prevent tar files from extracting files that can have the ability to navigate other paths (For instance, paths having
/home/user/../etc/passwd
as their filename.This feature is automatically built in Python 3.12 as
filter = 'data'
, and is ported back to earlier supported versions as well.This bug is a known security issue as CVE-2007-4559 in the National Institute of Standards and Technology (NIST) as a Medium vulnerability.
Description of how this change was tested
You can use the following Dockerfile for RHEL 10:
Run all the tests in the Docker container:
docker build -t vcs2l-test .