Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2mc-8fgj-3wmr

Опубликовано: 01 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation in tar-fs

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

Пакеты

Наименование

tar-fs

npm
Затронутые версииВерсия исправления

< 1.16.2

1.16.2

EPSS

Процентиль: 41%
0.00189
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
почти 7 лет назад

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

CVSS3: 7.5
debian
почти 7 лет назад

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File O ...

EPSS

Процентиль: 41%
0.00189
Низкий

7.5 High

CVSS3

Дефекты

CWE-20