MidnightBSD

Advisories for archive::tar_project

CVE-2018-12015 MEDIUM

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-59,

Products Affected

Vendor Product Version
canonical ubuntu_linux 16.04
canonical ubuntu_linux 12.04
apple mac_os_x *
canonical ubuntu_linux 17.10
canonical ubuntu_linux 18.04
perl perl *
archive::tar_project archive::tar *
canonical ubuntu_linux 14.04
debian debian_linux 8.0
netapp snap_creator_framework -
netapp snapdrive -
debian debian_linux 9.0
netapp oncommand_workflow_automation -
netapp data_ontap_edge -