| ▲ | boston_clone 2 days ago | |||||||
this is just one instance of a vulnerability associated with unzipping; a curious search would yield more. | ||||||||
| ▲ | cogman10 2 days ago | parent [-] | |||||||
A curious search reveals that vulnerabilities that do exist are of 2 flavors. 1. Standard C memory vulnerabilities 2. Unsafe file traversal while unzipping The entire second class is avoided in a fixed file format. The first class of vulnerabilities plague everything. A quick look at libxml2 CVEs shows that. | ||||||||
| ||||||||