Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If I read that correctly the problem is that it prints a filename that might include terminal control sequences that come from an attacker-controlled file name.

Comment in your second link:

https://github.com/libarchive/libarchive/pull/1609#issuecomm...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: