|
|
Message-ID: <fa8031b0-b1fb-4412-ad30-5fb11c3e5752@cs.ucla.edu> Date: Sun, 12 Apr 2026 09:14:20 -0700 From: Paul Eggert <eggert@...ucla.edu> To: Collin Funk <collin.funk1@...il.com>, oss-security@...ts.openwall.com Cc: Vahagn Vardanian <vahagn@...rays.io> Subject: Re: GNU tar: listing/extraction desynchronization allows hidden file injection On 2026-04-11 21:10, Collin Funk wrote: > I didn't look much at the others since I am not very familiar with tar. > Hopefully Paul can quickly tell if they are bogus or not. Yes, it's on my list of things to look at. As Collin hinted, much of that bug report is AI slop and this is why it's low priority for me.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.