Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j44m-qm6p-hp7m

Опубликовано: 01 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Arbitrary File Overwrite in tar

Versions of tar prior to 4.4.2 for 4.x and 2.2.2 for 2.x are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file.

Recommendation

For tar 4.x, upgrade to version 4.4.2 or later. For tar 2.x, upgrade to version 2.2.2 or later.

Пакеты

Наименование

tar

npm
Затронутые версииВерсия исправления

>= 3.0.0, < 4.4.2

4.4.2

Наименование

tar

npm
Затронутые версииВерсия исправления

< 2.2.2

2.2.2

EPSS

Процентиль: 73%
0.00762
Низкий

7.5 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 8.8
redhat
почти 8 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 7.5
nvd
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

CVSS3: 7.5
debian
почти 7 лет назад

A vulnerability was found in node-tar before version 4.4.2 (excluding ...

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю заменить существующее содержимое файла

EPSS

Процентиль: 73%
0.00762
Низкий

7.5 High

CVSS3

Дефекты

CWE-59