CVE-2018-12015
Public on 2018-06-07
Modified on 2019-10-23
Description
It was found that the Archive::Tar module did not properly sanitize symbolic links when extracting tar archives. An attacker, able to provide a specially crafted archive for processing, could use this flaw to write or overwrite arbitrary files in the context of the Perl interpreter.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | perl-Archive-Tar | 2019-09-13 | ALAS-2019-1287 | Fixed |
Amazon Linux 2 - Core | perl-Archive-Tar | 2019-10-21 | ALAS2-2019-1330 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.4 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
NVD | CVSSv2 | 6.4 | AV:N/AC:L/Au:N/C:N/I:P/A:P |
NVD | CVSSv3 | 7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |