Hi, I'm sorry Wes, but I don't understand your long list of urls :-( Can you elaborate?
I'm asking if there is a reason for allowing absolute paths by default. Maybe backward compatibility? 2017-03-09 20:33 GMT+01:00 Wes Turner <wes.tur...@gmail.com>: > Docs: https://docs.python.org/3/library/tarfile.html I didn't write a private email to security@ because as you pointed, the issue is known and *documented* in Python since 10 years. > https://python-security.readthedocs.io/ I wrote this doc :-) I just added notes about tarfile and zipfile. Victor _______________________________________________ Security-SIG mailing list Security-SIG@python.org https://mail.python.org/mailman/listinfo/security-sig