Open Source Security

By Josh Bressers

Python tarfile - 2022 is nothing like 2007

=> 🔊 Play episode (34 min) | Direct episode link | 💬 Share episode

Published October 09, 2022 7:00pm

Josh and Kurt talk about a newly rediscovered old python vulnerability. It raises a lot of questions about what was OK in 2007 vs what's OK in 2022. The issue is very complicated and has a wild story surrounding it. There is no reason to not fix this in 2022. Show Notes CVE-2007-4559 Red Hat Bug Register story Response from upstream Upstream patch ZippSlip Current upstream bug CSURF

=> Return to podcast

Proxy Information
Original URL
gemini://rocketcaster.xyz/episode/10660278128
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
2370.425831 milliseconds
Gemini-to-HTML Time
1.554472 milliseconds

This content has been proxied by September (ba2dc).