in reply to Security Hole in Archive::Tar ??
I would expect Tar.pm to do the same (will test it when I get home).
One approach you might take is to have your program inspect the pathnames on component files of a tarball to see if absolute paths or "upward" references are used. Your program can then provide the logic to deal with these cases.
I'll see if I can provide an example of this.
---v
|
|---|