PT-2020-19697 · U Root · U-Root

Georgios Gkitsas

·

Published

2020-09-01

·

Updated

2024-08-21

·

CVE-2020-7669

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions github.com/u-root/u-root/pkg/tarutil versions prior to 0.7.0
Description The issue affects the tar file extraction in the github.com/u-root/u-root/pkg/tarutil package, making it vulnerable to both leading and non-leading relative path traversal attacks. This can lead to arbitrary file write via archive extraction, also known as Zip Slip.
Recommendations For versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the tar file extraction functionality in the affected package until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-7669
GHSA-75QF-WGFJ-V652
GO-2022-0805
SNYK-GOLANG-GITHUBCOMUROOTUROOTPKGTARUTIL-570428

Affected Products

U-Root