AW: Re busybox tar hidden filename exploit

2024-06-24 Thread Walter Harms
Hi Ian, thx for the report. yes, i did not notice (and yes i check tars with -vt before installing). what do you expect now ? Do you have patch ? Do you want to start a discussion about possible solution ? (I use a strict ASCII-only policy in my projects to catch other traps also). What does gnut

Re: AW: Re busybox tar hidden filename exploit

2024-06-24 Thread Bernd Petrovitsch
Hi all! On 24/06/2024 10:03, Walter Harms wrote: [...] what do you expect now ? Do you have patch ? Do you want to start a discussion about possible solution ? Actually such filenames may exist in the filesystem so this point applies to `ls`, `find`, any other program listing files or handling