Date: Thu, 26 Aug 2004 03:53:44 +0000 (UTC) From: Tim Kientzle <kientzle@FreeBSD.org> To: src-committers@FreeBSD.org, cvs-src@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: src/lib/libarchive archive_read_extract.c Message-ID: <200408260353.i7Q3rikM095541@repoman.freebsd.org>
next in thread | raw e-mail | index | archive | help
kientzle 2004-08-26 03:53:44 UTC
FreeBSD src repository
Modified files:
lib/libarchive archive_read_extract.c
Log:
Don't edit permissions of pre-existing directories during extract.
This closes a security hole. Otherwise, libarchive will happily
extract into directories to which it lacks write permissions by
resetting the permissions during the extract.
Thanks to: Kris Kennaway
Revision Changes Path
1.34 +1 -1 src/lib/libarchive/archive_read_extract.c
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200408260353.i7Q3rikM095541>
