Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42496

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 8.2

Описание

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

A flaw was found in perl-Archive-Tar. Versions before 3.08 for Perl are vulnerable to a path traversal issue. An attacker can craft a malicious tar archive containing symlinks with targets outside the intended extraction directory. This vulnerability allows the attacker to read or write to arbitrary files on the system, leading to potential information disclosure or data corruption.

Отчет

This is an Important vulnerability in perl-Archive-Tar that allows for arbitrary file access due to a path traversal flaw when extracting specially crafted tar archives. An attacker could exploit this by creating a malicious archive containing symlinks that point outside the intended extraction directory, potentially leading to unauthorized information disclosure or data corruption on the system. This risk is elevated in environments where untrusted archives are processed.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-Archive-TarOut of support scope
Red Hat Enterprise Linux 10perl-Archive-TarFixedRHSA-2026:3085729.06.2026
Red Hat Enterprise Linux 8perlFixedRHSA-2026:3085129.06.2026
Red Hat Enterprise Linux 8perl-Archive-TarFixedRHSA-2026:3085229.06.2026
Red Hat Enterprise Linux 9perl-Archive-TarFixedRHSA-2026:3085629.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2481314perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
nvd
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

CVSS3: 9.1
msrc
около 2 месяцев назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory

CVSS3: 9.1
debian
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...

rocky
27 дней назад

Important: perl-Archive-Tar security update

8.2 High

CVSS3