Lucene search

K
osvGoogleOSV:GHSA-XF7W-R453-M56C
HistoryMay 30, 2019 - 5:19 p.m.

Arbitrary File Overwrite in fstream

2019-05-3017:19:34
Google
osv.dev
28

EPSS

0.002

Percentile

62.2%

Versions of fstream prior to 1.0.12 are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system’s file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

Recommendation

Upgrade to version 1.0.12 or later.