Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12015

Опубликовано: 07 июн. 2018
Источник: debian

Описание

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
perlfixed5.26.2-6package

Примечания

  • https://rt.cpan.org/Public/Bug/Display.html?id=125523

  • https://github.com/jib/archive-tar-new/commit/ae65651eab053fc6dc4590dbb863a268215c1fc5

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

CVSS3: 5.4
redhat
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

CVSS3: 7.5
nvd
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

suse-cvrf
больше 7 лет назад

Security update for perl

suse-cvrf
больше 7 лет назад

Security update for perl