Описание
Arbitrary File Overwrite in fstream
Versions of fstream prior to 1.0.12 are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
Recommendation
Upgrade to version 1.0.12 or later.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-13173
- https://github.com/npm/fstream/commit/6a77d2fa6e1462693cf8e46f930da96ec1b0bb22
- https://usn.ubuntu.com/4123-1
- https://www.npmjs.com/advisories/886
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00052.html
Пакеты
fstream
< 1.0.12
1.0.12
Связанные уязвимости
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extra ...