2 pointsby ivytheaxolotl8 hours ago2 comments
  • theamk7 hours ago
    Original discussion, for the curious: [0]

    Something of the note: despite the scary name, this is a "parsing mismatch" vulnerability. The discovery what was that one could make a tar file which would safe in the "tar" tool, but when extracted by an affected rust crate, it would find more files, possibly malicious. By itself, it's fine - if you are extracting untrusted tar files without the filter, you are going to have a bad time, vulnerability or not. The vulnerability would only occur if you have a combination of files: like a security scanner which uses one library, followed by the real app which uses a different library. Then the bad code could escape security scanner's attention.

    [0] https://news.ycombinator.com/item?id=45665513

  • 8 hours ago
    undefined