Public bug reported: Zip files might include symbolic links which could be abused by an attacker to escape from restricted directories and/or from restricted environments. The attached patch includes a command line option -g which does not apply the symbolic links when zip file is extracted. In case a zip file includes a symbolic link a file is created instead containing the target of the symbolic link.
** Affects: unzip (Ubuntu) Importance: Undecided Status: New ** Patch added: "do_not_apply_symlinks.patch" https://bugs.launchpad.net/bugs/1636207/+attachment/4766457/+files/do_not_apply_symlinks.patch -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1636207 Title: Patch proposal to do not apply symbolic links included in zip files. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1636207/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs