Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf7w-r453-m56c

Опубликовано: 30 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Arbitrary File Overwrite in fstream

Versions of fstream prior to 1.0.12 are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

Recommendation

Upgrade to version 1.0.12 or later.

Пакеты

Наименование

fstream

npm
Затронутые версииВерсия исправления

< 1.0.12

1.0.12

EPSS

Процентиль: 83%
0.02416
Низкий

7.5 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.3
redhat
больше 7 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
nvd
около 7 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
debian
около 7 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extra ...

suse-cvrf
около 7 лет назад

Security update for nodejs8

EPSS

Процентиль: 83%
0.02416
Низкий

7.5 High

CVSS3

Дефекты

CWE-59