Public bug reported:

Zip files might include symbolic links which could be abused by an
attacker to escape from restricted directories and/or from restricted
environments. The attached patch includes a command line option -g which
does not apply the symbolic links when zip file is extracted. In case a
zip file includes a symbolic link a file is created instead containing
the target of the symbolic link.

** Affects: unzip (Ubuntu)
     Importance: Undecided
         Status: New

** Patch added: "do_not_apply_symlinks.patch"
   
https://bugs.launchpad.net/bugs/1636207/+attachment/4766457/+files/do_not_apply_symlinks.patch

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1636207

Title:
  Patch proposal to do not apply symbolic links included in zip files.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1636207/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to