Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx64-wwv2-hcqq

Опубликовано: 06 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

astral-tokio-tar: unpack_in can chmod arbitrary directories by following symlinks

Impact

In versions 0.6.0 and earlier of astral-tokio-tar, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.

See GHSA-j4xf-2g29-59ph for the equivalent flaw in the tar crate.

Patches

Versions 0.6.1 and newer of astral-tokio-tar use fs::symlink_metdata rather than fs::metadata, avoiding the traversal.

Workarounds

Users are advised to upgrade to version 0.6.1 or newer to address this advisory.

Users should experience no breaking changes as a result of the patch above.

Resources

  • GHSA-j4xf-2g29-59ph for the original tar vulnerability

Attribution

  • Reporter: Adam Harvey (@lawngnome)

Пакеты

Наименование

astral-tokio-tar

rust
Затронутые версииВерсия исправления

<= 0.6.0

0.6.1

2.7 Low

CVSS4

Дефекты

CWE-61

2.7 Low

CVSS4

Дефекты

CWE-61