Issue #6972: keep the warning about untrusted extraction and mention

the version it was improved in.
This commit is contained in:
Gregory P. Smith 2013-02-07 22:15:04 -08:00
parent d03f467dc2
commit f1319d81f7

View file

@ -232,9 +232,15 @@ ZipFile Objects
be a subset of the list returned by :meth:`namelist`. *pwd* is the password
used for encrypted files.
.. note::
.. warning::
See :meth:`extract` note.
Never extract archives from untrusted sources without prior inspection.
It is possible that files are created outside of *path*, e.g. members
that have absolute filenames starting with ``"/"`` or filenames with two
dots ``".."``.
.. versionchanged:: 3.2.4
The zipfile module attempts to prevent that. See :meth:`extract` note.
.. method:: ZipFile.printdir()