[RESEND][PATCH] fix masking of malicious path traversals in archive content listings

2024-10-11 Thread Ian Norton
Prevent unprintable bytes including terminal escapes being printed when listing tar file contents in a terminal as this can be used to hide malicious archive content from users prior to unpacking a file. Re #16018 Also added bb_safe_dump_str() to include/libbb.h --- archival/libarchive/header_lis

Re: [EXTERNAL] [RESEND(4) PATCH] archival: disallow path traversals (CVE-2023-39810)

2024-10-11 Thread Ian Norton
FYI, This seems also related to https://bugs.busybox.net/show_bug.cgi?id=16018 (my patch for fixing that seems to have got lost in the mailing list noise) From: busybox on behalf of Peter Kaestle Date: Wednesday 2 October 2024 at 09:12 To: "busybox@busybox.net" , Denys Vlasenko Cc: "martin.