Loading
Python safe_tarfile: further adjustments for old python
This is used only by domain backup restore. With old versions (< 3.8) of Python, a bad tarfile could write in the wrong place (CVE-2007-4559). This sounds worse than it is, because writing in the right place already gives the attacker domain admin.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16103
Checklist
- Commits have
Signed-off-by:with name/author being identical to the commit author - (optional) This MR is just one part towards a larger feature.
- (optional, if backport required) Bugzilla bug filed and
BUG:tag added - Test suite updated with functionality tests
- Test suite updated with negative tests
- Documentation updated
- CI timeout is 3h or higher (see Settings/CICD/General pipelines/ Timeout)
Reviewer's checklist:
- There is a test suite reasonably covering new functionality or modifications
- Function naming, parameters, return values, types, etc., are consistent
and according to
README.Coding.md - This feature/change has adequate documentation added
- No obvious mistakes in the code