Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45491

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 6.2

Описание

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

A flaw was found in .NET's System.Formats.Tar library. When extracting a specially crafted TAR archive containing symbolic links, the TarFile.ExtractToDirectory() method may incorrectly follow those links and write files outside the intended extraction directory. An attacker could exploit this issue to create or overwrite files in locations accessible to the extracting process, potentially leading to unauthorized file modification.

Отчет

This vulnerability affects .NET's TAR archive extraction functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The flaw occurs in System.Formats.Tar when processing TAR archives containing symbolic links. During extraction, the TarFile.ExtractToDirectory() method may incorrectly follow symlink paths and write files outside the intended extraction directory. Successful exploitation requires a vulnerable application to process a specially crafted TAR archive. An attacker could use this behavior to create or overwrite files in locations accessible to the extracting process, potentially affecting system or application integrity. The vulnerability is a symlink path traversal issue that results in unauthorized file modification outside the designated extraction directory. The primary security impact is integrity compromise through arbitrary file writes.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2487164dotnet: .NET: Local file tampering via link following vulnerability

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 2 месяцев назад

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

CVSS3: 6.2
nvd
около 2 месяцев назад

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

CVSS3: 6.2
msrc
около 2 месяцев назад

.NET Tampering Vulnerability

CVSS3: 6.8
github
около 2 месяцев назад

Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability

CVSS3: 6.2
fstec
около 2 месяцев назад

Уязвимость метода TarFile.ExtractToDirectory программной платформы .NET, позволяющая нарушителю получить доступ на чтение и изменение данных

6.2 Medium

CVSS3