Total vulnerabilities in the database
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
canonical / ubuntu_linux | 17.10 | 17.10.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
perl / perl | - | 5.26.2.x |
archive--tar_project / archive--tar | - | 2.28.x |
apple / mac_os_x | - | 10.14.4 |