Описание
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.1.2+~cs2.0.4-1 |
| esm-apps/jammy | released | 2.1.1-6ubuntu0.22.04.1~esm1 |
| esm-apps/noble | released | 2.1.1-6ubuntu0.24.04.1~esm1 |
| esm-apps/resolute | not-affected | 3.1.2+~cs2.0.4-1 |
| jammy | needed | |
| noble | needed | |
| plucky | ignored | end of life, was needs-triage |
| questing | released | 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1 |
| resolute | not-affected | 3.1.2+~cs2.0.4-1 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
Связанные уязвимости
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
tar-fs provides filesystem bindings for tar-stream. Versions prior to ...
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Уязвимость пакета tar-fs библиотеки для потоковой обработки файлов формата tar tar-stream, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS