CVE-2018-20990: High severity tar vulnerability
Published Aug 26, 2019
·Updated
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
Affected Software
1 affected component
Tar Project Tar<0.4.16
Event History
Aug 26, 2019
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20990?
CVE-2018-20990 is an issue in the tar crate before version 0.4.16 for Rust that allows arbitrary file overwrite via a symlink or hardlink in a TAR archive.
2
How severe is CVE-2018-20990?
CVE-2018-20990 has a severity rating of 7.5 (high).
3
What software is affected by CVE-2018-20990?
The Tar Project's tar version up to (but excluding) 0.4.16 is affected by CVE-2018-20990.
4
How can file overwrite occur using CVE-2018-20990?
File overwrite can occur through the exploitation of symlinks or hardlinks in a TAR archive.
5
Where can I find more information about CVE-2018-20990?
More information about CVE-2018-20990 can be found at https://rustsec.org/advisories/RUSTSEC-2018-0002.html.