Количество 13
Количество 13
GHSA-8p37-q9qq-hgx8
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...
RLSA-2026:30857
Important: perl-Archive-Tar security update
RLSA-2026:30856
Important: perl-Archive-Tar security update
ELSA-2026-30857
ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT)
ELSA-2026-30856
ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT)
ELSA-2026-30852
ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT)
RLSA-2026:30851
Important: perl:5.32 security update
ELSA-2026-30851
ELSA-2026-30851: perl:5.32 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8p37-q9qq-hgx8 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attac ... | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
RLSA-2026:30857 Important: perl-Archive-Tar security update | 0% Низкий | 27 дней назад | ||
RLSA-2026:30856 Important: perl-Archive-Tar security update | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-30857 ELSA-2026-30857: perl-Archive-Tar security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-30856 ELSA-2026-30856: perl-Archive-Tar security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-30852 ELSA-2026-30852: perl-Archive-Tar security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:30851 Important: perl:5.32 security update | около 1 месяца назад | |||
ELSA-2026-30851 ELSA-2026-30851: perl:5.32 security update (IMPORTANT) | около 1 месяца назад |
Уязвимостей на страницу