emaste b4641924a1 MFC r281311: ar: Disallow directory traversal
Set ARCHIVE_EXTRACT_SECURE_SYMLINKS and ARCHIVE_EXTRACT_SECURE_NODOTDOT
  as in bsdtar to prevent extraction of archive entries whose pathnames
  contain .. or whose target directory would be altered by a symlink.
  Also disallow absolute pathnames.

  We don't currently provide an option to disable this behaviour (as
  bsdtar's -P does). It is unlikely to be a problem in practice for ar(1),
  but the -P option is not currently used and available if we want to
  consider it for this purpose.

Obtained from:	ELF tool chain ar, Ticket #474
Relnotes:	Yes
Sponsored by:	The FreeBSD Foundation
2015-04-24 15:48:23 +00:00
..
2011-12-23 00:31:26 +00:00
2012-02-25 10:58:02 +00:00