github doronz88/pymobiledevice3 v11.23.1

3 hours ago

Highlights

🐛 A recursive AFC pull stays inside its destination

Pulling a directory built each local path from names the device supplied, without checking them. A .. entry in a directory listing, or a symlink whose target ends in .., made the pull write one level above the folder you chose. Both names now go through the same safe_paths validation the backup, crash-report and symbol-fetching code already use, and the pull fails with DevicePathError (or skips the entry under --ignore-errors).

This also covers an ordinary tree containing a link to its own parent, which used to recurse until the path grew too long.

pymobiledevice3 afc pull /DCIM ./out

What's Changed

New Contributors

Full Changelog: v11.23.0...v11.23.1

Don't miss a new pymobiledevice3 release

NewReleases is sending notifications on new releases.