First published: Mon Aug 26 2019(Updated: )
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tar Project Tar | <0.4.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20990 is an issue in the tar crate before version 0.4.16 for Rust that allows arbitrary file overwrite via a symlink or hardlink in a TAR archive.
CVE-2018-20990 has a severity rating of 7.5 (high).
The Tar Project's tar version up to (but excluding) 0.4.16 is affected by CVE-2018-20990.
File overwrite can occur through the exploitation of symlinks or hardlinks in a TAR archive.
More information about CVE-2018-20990 can be found at https://rustsec.org/advisories/RUSTSEC-2018-0002.html.