Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf7w-r453-m56c

Опубликовано: 30 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Arbitrary File Overwrite in fstream

Versions of fstream prior to 1.0.12 are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

Recommendation

Upgrade to version 1.0.12 or later.

Пакеты

Наименование

fstream

npm
Затронутые версииВерсия исправления

< 1.0.12

1.0.12

EPSS

Процентиль: 62%
0.0043
Низкий

7.5 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.3
redhat
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
nvd
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
debian
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extra ...

suse-cvrf
больше 6 лет назад

Security update for nodejs8

EPSS

Процентиль: 62%
0.0043
Низкий

7.5 High

CVSS3

Дефекты

CWE-59