← 返回首页
[3.9] gh-99889: Fix directory traversal security flaw in uu.decode() (GH-104096) by miss-islington · Pull Request #104331 · python/cpython · GitHub
Skip to content

Navigation Menu

Toggle navigation
Sign in
Appearance settings
Search or jump to...

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Resetting focus

[3.9] gh-99889: Fix directory traversal security flaw in uu.decode() (GH-104096)#104331

Merged
ambv merged 1 commit into
python:3.9from
miss-islington:backport-0aeda29-3.9
May 22, 2023
Merged

[3.9] gh-99889: Fix directory traversal security flaw in uu.decode() (GH-104096)#104331
ambv merged 1 commit into
python:3.9from
miss-islington:backport-0aeda29-3.9

Conversation

Copy link
Copy Markdown
Contributor

miss-islington commented May 9, 2023
edited by bedevere-bot
Loading

  • Fix directory traversal security flaw in uu.decode()
  • also check absolute paths and os.altsep
  • Add a regression test.

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com
Co-authored-by: Gregory P. Smith greg@krypto.org [Google]

…ythonGH-104096) * Fix directory traversal security flaw in uu.decode() * also check absolute paths and os.altsep * Add a regression test. --------- (cherry picked from commit 0aeda29) Co-authored-by: Sam Carroll <70000253+samcarroll42@users.noreply.github.com> Co-authored-by: Gregory P. Smith <greg@krypto.org> [Google]
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-security A security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Footer

© 2026 GitHub, Inc.