Comment 1 for bug 885167

Revision history for this message
David (d--) wrote :

One more possible bug (I don't know if this is reachable) is that the tarfile.extractall method is used in the
 static method _untarzip_image. This method is also vulnerable to path traversal (as per the warning in the tarfile module documentation).