REDHAT-BUG-2433645: Path Traversal
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
node-tarto a version that resolves this vulnerability.Fixed in 7.5.7
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2433645?
The severity of REDHAT-BUG-2433645 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2433645?
To fix REDHAT-BUG-2433645, update node-tar to version 7.5.7 or later.
What type of vulnerability is REDHAT-BUG-2433645?
REDHAT-BUG-2433645 is a Path Traversal vulnerability found in node-tar.
Which versions of node-tar are affected by REDHAT-BUG-2433645?
Versions of node-tar prior to 7.5.7 are affected by REDHAT-BUG-2433645.
What can an attacker do with REDHAT-BUG-2433645?
An attacker can exploit REDHAT-BUG-2433645 to create a malicious TAR archive that bypasses path traversal protections.