-
Notifications
You must be signed in to change notification settings - Fork 15
Open
Description
I maintain Golang bindings for unarr at https://github.com/gen2brain/go-unarr and there is this issue reported with tar archives gen2brain/go-unarr#21, along with this CVE GHSA-v9j4-cp63-qv62. Unfortunately, I don't have a sample of such an archive or a method to create such an archive. I see there are such samples at https://github.com/jwilk/traversal-archives but not sure if these can be used to reproduce the issue.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels