Commit b70102d
committed
Add a check to ensure the name resolves relative to the tmpdir
Closes pypa#4946: Security Fix for CVE-2025-47273
From 250a6d1 Mon Sep 17 00:00:00 2001
From: "Jason R. Coombs" <[email protected]>
Date: Sat, 19 Apr 2025 13:03:47 -0400
---
Adapted to integrate into 68.0.0.2 this required the creation of the
staticmethod _resolve_download_filename which was not present in this
version.1 parent 24189c3 commit b70102d
1 file changed
+30
-4
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
801 | 801 | | |
802 | 802 | | |
803 | 803 | | |
804 | | - | |
805 | | - | |
806 | | - | |
807 | | - | |
| 804 | + | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
| 814 | + | |
| 815 | + | |
| 816 | + | |
| 817 | + | |
| 818 | + | |
| 819 | + | |
| 820 | + | |
| 821 | + | |
| 822 | + | |
808 | 823 | | |
809 | 824 | | |
810 | 825 | | |
| |||
816 | 831 | | |
817 | 832 | | |
818 | 833 | | |
| 834 | + | |
| 835 | + | |
| 836 | + | |
| 837 | + | |
| 838 | + | |
| 839 | + | |
| 840 | + | |
| 841 | + | |
| 842 | + | |
| 843 | + | |
| 844 | + | |
819 | 845 | | |
820 | 846 | | |
821 | 847 | | |
| |||
0 commit comments