Re: CVE-2016-6232 / kdelibs4

2016-07-18 Thread Chris Lamb
> Looks like this is an issue if you try to extract a tar file that > contains relative paths outside the archives root. Is this considered a > security issue we need to address? (Replying quickly here so apologies for the lack of context/references but there was previous discussion on this topic

CVE-2016-6232 / kdelibs4

2016-07-18 Thread Brian May
Hello, Just wondering if I we need to fix CVE-2016-6232 in kdelib4 or not? Looks like this is an issue if you try to extract a tar file that contains relative paths outside the archives root. Is this considered a security issue we need to address? Such as this one that comes as a test case: # t