Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12015

Опубликовано: 07 июн. 2018
Источник: redhat
CVSS3: 5.4
EPSS Средний

Описание

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

It was found that the Archive::Tar module did not properly sanitize symbolic links when extracting tar archives. An attacker, able to provide a specially crafted archive for processing, could use this flaw to write or overwrite arbitrary files in the context of the Perl interpreter.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perl-Archive-TarWill not fix
Red Hat Enterprise Linux 6perlWill not fix
Red Hat Enterprise Linux 8perl-Archive-TarNot affected
Red Hat Software Collectionsrh-perl520-perl-Archive-TarWill not fix
Red Hat Software Collectionsrh-perl524-perl-Archive-TarOut of support scope
Red Hat Software Collectionsrh-perl526-perl-Archive-TarWill not fix
Red Hat Software Collectionsrh-perl530-perl-Archive-TarNot affected
Red Hat Enterprise Linux 7perl-Archive-TarFixedRHSA-2019:209706.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1588760perl: Directory traversal in Archive::Tar

EPSS

Процентиль: 94%
0.15065
Средний

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

CVSS3: 7.5
nvd
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

CVSS3: 7.5
debian
больше 7 лет назад

In Perl through 5.26.2, the Archive::Tar module allows remote attacker ...

suse-cvrf
больше 7 лет назад

Security update for perl

suse-cvrf
больше 7 лет назад

Security update for perl

EPSS

Процентиль: 94%
0.15065
Средний

5.4 Medium

CVSS3