REDHAT-BUG-2498116: High severity npm/node-tar vulnerability
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
node-tarto a version that resolves this vulnerability.Fixed in 7.5.18
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498116?
The severity of REDHAT-BUG-2498116 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2498116?
To fix REDHAT-BUG-2498116, upgrade node-tar to version 7.5.18 or later.
What is the risk level associated with REDHAT-BUG-2498116?
The risk level associated with REDHAT-BUG-2498116 is rated at 33.
What is the impact of REDHAT-BUG-2498116?
The impact of REDHAT-BUG-2498116 can cause the archive scanner to fail to make progress due to repeatedly parsing the same header.
What versions of node-tar are affected by REDHAT-BUG-2498116?
Versions of node-tar prior to 7.5.18 are affected by REDHAT-BUG-2498116.