develooper Front page | perl.qa | Postings from November 2008

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

Thread Previous | Thread Next
From:
David Golden
Date:
November 13, 2008 03:26
Subject:
Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists
Message ID:
5d4beb40811130326h133370b4ibb7f80a35962f9f7@mail.gmail.com
On Thu, Nov 13, 2008 at 3:39 AM, Shlomi Fish <shlomif@iglu.org.il> wrote:
>> What I was expressing is that the CPAN shell can do the twiddling to strip
>> flags at the point of extraction, rather than PAUSE stopping it at the
>> gate. Archive::Tar already does this (see
>> $Archive::Tar::INSECURE_EXTRACT_MODE).
>
> Archive::Tar does, but Archive::Extract (which CPANPLUS uses) doesn't.

It was a bug.  Addressed in 0.28 as a result of these discussions.
The next non-development release of CPANPLUS will use the new
Archive::Extract and close the security hole under discussion.

-- David

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About