Skip to content

Conversation

miss-islington
Copy link
Contributor

@miss-islington miss-islington commented May 9, 2023

  • Fix directory traversal security flaw in uu.decode()
  • also check absolute paths and os.altsep
  • Add a regression test.

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll [email protected]
Co-authored-by: Gregory P. Smith [email protected] [Google]

…ythonGH-104096)

* Fix directory traversal security flaw in uu.decode()
* also check absolute paths and os.altsep
* Add a regression test.

---------

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll <[email protected]>
Co-authored-by: Gregory P. Smith <[email protected]> [Google]
@ned-deily ned-deily merged commit 1ce801b into python:3.7 May 27, 2023
@miss-islington miss-islington deleted the backport-0aeda29-3.7 branch May 27, 2023 07:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type-security A security issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants