Skip to main content
Loading…
    CVE-2015-8768 — click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges — CVE Database · The Intelligence Room