You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Change https://golang.org/cl/290650 mentions this issue: [release-branch.go1.15] archive/tar: detect out of bounds accesses in PAX records resulting from padded lengths
Thanks for making this backport request. This bug is not considered a security problem and has been around for many years before it was first reported. There is a really good workaround: to catch the possible panic when handling untrusted tar input.
This isn't meeting the criteria for backport to Go 1.15 and 1.14, so we'll leave the fix for Go 1.16 and onwards.
@odeke-em requested issue #40196 to be considered for backport to the next 1.15 minor release.
The text was updated successfully, but these errors were encountered: