mirror of
https://github.com/bytecodealliance/wasm-micro-runtime.git
synced 2025-10-23 01:11:16 +00:00
Fix a widespread bug named CVE-2007-4559, which is a 15 year old bug in the Python tarfile package. By using extract() or extractall() on a tarfile object without sanitizing input, a maliciously crafted .tar file could perform a directory path traversal attack. This patch essentially checks to see if all tarfile members will be extracted safely and throws an exception otherwise. |
||
|---|---|---|
| .. | ||
| patches | ||
| build_wasi_sdk.py | ||