patch CVE-2007-4559

This commit is contained in:
OwnedByWuigi 2026-03-01 17:44:02 +00:00
commit 52e4409d48

View file

@ -136,8 +136,26 @@ def build_from_context(docker_bin, context_path, prefix, tag=None):
d = tempfile.mkdtemp()
try:
with tarfile.open(context_path, 'r:gz') as tf:
tf.extractall(d)
def is_within_directory(directory, target):
abs_directory = os.path.abspath(directory)
abs_target = os.path.abspath(target)
prefix = os.path.commonprefix([abs_directory, abs_target])
return prefix == abs_directory
def safe_extract(tar, path=".", members=None, *, numeric_owner=False):
for member in tar.getmembers():
member_path = os.path.join(path, member.name)
if not is_within_directory(path, member_path):
raise Exception("Attempted Path Traversal in Tar File")
tar.extractall(path, members, numeric_owner=numeric_owner)
safe_extract(tf, d)
# If we wanted to do post-processing of the Dockerfile, this is
# where we'd do it.