Fix path traversal issue when extracting an .okular file

Authored by aacid on Sep 3 2018, 7:14 PM.

Description

Fix path traversal issue when extracting an .okular file

Summary:
With specially crafted .okular files you can trick okular to create temporary files outside the temporary folder

We fix that by making sure the file doesn't have folders since the ones we create don't

BUGS: 398096

Subscribers: okular-devel

Tags: Okular

Differential Revision: https://phabricator.kde.org/D15192

Details

Committed
aacidSep 3 2018, 7:14 PM
Differential Revision
D15192: Fix path traversal issue when extracting an .okular file
Parents
R223:86858e6cb025: GIT_SILENT made messages (after extraction)
Branches
Unknown
Tags
Unknown
References
tag: v18.08.1