First published: Tue Jun 05 2018(Updated: )
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Credit: Jakub Wilk Jayakrishna Menon Eiichi Tsukata cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Mojave | <10.14.4 | 10.14.4 |
Apple High Sierra | ||
Apple Sierra | ||
redhat/perl-Archive-Tar | <2.28 | 2.28 |
debian/perl | <=5.26.2-5<=5.24.1-1<=5.28.0~rc2-1<=5.20.2-1 | 5.26.2-6 5.20.2-3+deb8u11 5.24.1-3+deb9u4 5.28.0-1 |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Perl Perl | <=5.26.2 | |
Archive\ \ | <=2.28 | |
Apple Mac OS X | <10.14.4 | |
Netapp Data Ontap Edge | ||
NetApp OnCommand Workflow Automation | ||
NetApp Snap Creator Framework | ||
Netapp Snapdrive Unix | ||
ubuntu/perl | <5.26.0-8ubuntu1.2 | 5.26.0-8ubuntu1.2 |
ubuntu/perl | <5.26.1-6ubuntu0.1 | 5.26.1-6ubuntu0.1 |
ubuntu/perl | <5.18.2-2ubuntu1.6 | 5.18.2-2ubuntu1.6 |
ubuntu/perl | <5.26.2-6 | 5.26.2-6 |
ubuntu/perl | <5.22.1-9ubuntu0.5 | 5.22.1-9ubuntu0.5 |
debian/perl | 5.32.1-4+deb11u3 5.32.1-4+deb11u4 5.36.0-7+deb12u1 5.40.0-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this Perl vulnerability is CVE-2018-12015.
The vulnerability allows remote attackers to bypass a directory-traversal protection mechanism and overwrite arbitrary files.
The affected software versions include Perl through 5.26.2 and Archive::Tar up to version 2.28.
The severity level of this vulnerability is high, with a CVSS score of 7.5.
You can find more information about this vulnerability at the following references: [1] [2] [3]