All vulnerabilities
CVE-2018-20834
Arbitrary File Overwrite in tar
Description
Versions of tar prior to 4.4.2 for 4.x and 2.2.2 for 2.x are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file.
Recommendation
For tar 4.x, upgrade to version 4.4.2 or later.For tar 2.x, upgrade to version 2.2.2 or later.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
JavaScript
Publish Date
May 1, 2019
Modified Date
November 29, 2023
Score Vector
Affected Versions

