You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Trellix security team submitted a patch for CVE-2007-4559 in #1099, which we declined for some good reasons.
After thinking about this, I think it would actually be very wise for us to patch this exactly because of our use of tarfiles in datastacks. The intent of a datastack archive is to allow someone to share their data with us, and a maliciously-constructed datastack archive would be a very easy way to take advantage. So we might as well patch it, even if just in case.
The text was updated successfully, but these errors were encountered:
The Trellix security team submitted a patch for CVE-2007-4559 in #1099, which we declined for some good reasons.
After thinking about this, I think it would actually be very wise for us to patch this exactly because of our use of tarfiles in datastacks. The intent of a datastack archive is to allow someone to share their data with us, and a maliciously-constructed datastack archive would be a very easy way to take advantage. So we might as well patch it, even if just in case.
The text was updated successfully, but these errors were encountered: