HIGH
A vulnerability was found in tar-fs before 1.16.2
Published Apr 30, 2019
7.5
HIGHCVSS 3.0
EPSS 2.36%
Description
A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.
Affected products
No data.
- < 1.16.2
No data.
No Red Hat product state for this CVE.
tar-fs
npm
Introduced 0 Fixed 1.16.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | tar-fs | 0 | 1.16.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-x2mc-8fgj-3wmr Advisory
- https://github.com/mafintosh/tar-fs/commit/06672828e6fa29ac8551b1b6f36c852a9a3c58a2 x_refsource_MISCPatchThird Party Advisory
- https://github.com/mafintosh/tar-fs/compare/d590fc7...a35ce2f x_refsource_MISCPatchThird Party Advisory
- https://hackerone.com/reports/344595 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20835
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-x2mc-8fgj-3wmr | Advisory | |
| https://github.com/mafintosh/tar-fs/commit/06672828e6fa29ac8551b1b6f36c852a9a3c58a2 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/mafintosh/tar-fs/compare/d590fc7...a35ce2f | x_refsource_MISCPatchThird Party Advisory | |
| https://hackerone.com/reports/344595 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20835 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2019
Updated Aug 5, 2024
Reserved Apr 30, 2019
Link CVE-2018-20835
CISA Vulnrichment
GHSA-X2MC-8FGJ-3WMR Updated n/a