Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59874

Опубликовано: 08 июл. 2026
Источник: debian

Описание

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-tarfixed7.5.19+~4.0.1-1package
node-tarno-dsatrixiepackage

Примечания

  • https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w

  • Fixed by: https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5 (v7.5.18)

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

(node-tar is a tar archive manipulation library for Node.js. Prior to 7 ...)

CVSS3: 7.5
redhat
25 дней назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

CVSS3: 7.5
nvd
24 дня назад

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.

msrc
21 день назад

node-tar: Negative tar entry size causes infinite loop in archive replace

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость функции tar.replace() библиотеки node-tar программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании