PT-2019-10267 · Npm · Tar-Fs
Max
·
Publicado
2019-04-30
·
Atualizado
2019-05-03
·
CVE-2018-20835
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
tar-fs versions prior to 1.16.2
Description:
A vulnerability exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink, allowing an Arbitrary File Overwrite issue. This occurs because the plain file content replaces the existing file content.
Recommendations:
For versions prior to 1.16.2, update to version 1.16.2 or later to resolve the issue.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tar-Fs