Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfjr-3jmm-4g9v

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Symlink Arbitrary File Overwrite in tar

Versions of tar prior to 2.0.0 are affected by an arbitrary file write vulnerability. The vulnerability occurs because tar does not verify that extracted symbolic links to not resolve to targets outside of the extraction root directory.

Recommendation

Update to version 2.0.0 or later

Пакеты

Наименование

tar

npm
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 58%
0.00365
Низкий

7.5 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

redhat
около 10 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
nvd
больше 8 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

CVSS3: 7.5
debian
больше 8 лет назад

The tar package before 2.0.0 for Node.js allows remote attackers to wr ...

EPSS

Процентиль: 58%
0.00365
Низкий

7.5 High

CVSS3

Дефекты

CWE-59