Lucene search

K
osvGoogleOSV:GHSA-J44M-QM6P-HP7M
HistoryMay 01, 2019 - 6:37 p.m.

Arbitrary File Overwrite in tar

2019-05-0118:37:31
Google
osv.dev
12

0.003 Low

EPSS

Percentile

70.8%

Versions of tar prior to 4.4.2 for 4.x and 2.2.2 for 2.x are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink will overwrite the system’s file with the contents of the extracted file.

Recommendation

For tar 4.x, upgrade to version 4.4.2 or later.
For tar 2.x, upgrade to version 2.2.2 or later.

CPENameOperatorVersion
tarlt4.4.2
tarlt2.2.2
targe3.0.0

0.003 Low

EPSS

Percentile

70.8%