Browse Source

Adding tarfile member sanitization to extractall()

TrellixVulnTeam 3 năm trước cách đây
mục cha
commit
e692cc1448

+ 20 - 1
clang/host/linux-x86/clang-r428724/python3/lib/python3.9/tarfile.py

@@ -2541,7 +2541,26 @@ def main():
 
         if is_tarfile(src):
             with TarFile.open(src, 'r:*') as tf:
-                tf.extractall(path=curdir)
+                def is_within_directory(directory, target):
+                    
+                    abs_directory = os.path.abspath(directory)
+                    abs_target = os.path.abspath(target)
+                
+                    prefix = os.path.commonprefix([abs_directory, abs_target])
+                    
+                    return prefix == abs_directory
+                
+                def safe_extract(tar, path=".", members=None, *, numeric_owner=False):
+                
+                    for member in tar.getmembers():
+                        member_path = os.path.join(path, member.name)
+                        if not is_within_directory(path, member_path):
+                            raise Exception("Attempted Path Traversal in Tar File")
+                
+                    tar.extractall(path, members, numeric_owner=numeric_owner) 
+                    
+                
+                safe_extract(tf, path=curdir)
             if args.verbose:
                 if curdir == '.':
                     msg = '{!r} file is extracted.'.format(src)