Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13173

Опубликовано: 15 мая 2019
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs:10/nodejsNot affected
Red Hat Mobile Application Platform 4nodejs-fstreamOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat Software Collectionsrh-nodejs10-nodejsNot affected
Red Hat Software Collectionsrh-nodejs8-nodejsWill not fix
Red Hat Virtualization 4ovirt-engine-api-explorerNot affected
Red Hat Virtualization 4ovirt-engine-dashboardNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=1710570nodejs-fstream: File overwrite in fstream.DirWriter() function

EPSS

Процентиль: 62%
0.0043
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
nvd
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

CVSS3: 7.5
debian
больше 6 лет назад

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extra ...

suse-cvrf
больше 6 лет назад

Security update for nodejs8

suse-cvrf
больше 6 лет назад

Security update for nodejs10

EPSS

Процентиль: 62%
0.0043
Низкий

7.3 High

CVSS3