Re: [dwm] [announce] sltar-0.2.1

From: Nico Golde <nico_AT_ngolde.de>
Date: Wed, 19 Dec 2007 23:08:28 +0100

Hi Enno,
* Enno Gottox Boland <gottox_AT_gmail.com> [2007-12-19 17:12]:
> I wrote a very small tarball extractor: (73sloc).

Why does it suck less? SLOC can't be the only argument,
functionality combined with SLOC is an argument.

> tar.gz:
> http://s01.de/~gottox/files/sltar/sltar-0.2.1.tar.gz

Seems to work but you should add more checks on extracting
files. This version is at least prone to directory traversal
vulnerabilities.
Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Received on Wed Dec 19 2007 - 23:08:18 UTC

This archive was generated by hypermail 2.2.0 : Sun Jul 13 2008 - 15:12:51 UTC