Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 657778 - dev-lang/perl: CVE-2018-12015: Archive::Tar: directory traversal vulnerability
Summary: dev-lang/perl: CVE-2018-12015: Archive::Tar: directory traversal vulnerability
Status: RESOLVED DUPLICATE of bug 657968
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugs.debian.org/900834
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-06-11 00:44 UTC by Ian Zimmerman
Modified: 2018-06-16 04:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ian Zimmerman 2018-06-11 00:44:13 UTC
Quoting $URL:

> By default, the Archive::Tar module doesn't allow extracting files
> outside the current working directory. However, you can bypass this
> secure extraction mode easily by putting a symlink and a regular file
> with the same name into the tarball.
Comment 1 Kent Fredric (IRC: kent\n) (RETIRED) gentoo-dev 2018-06-16 04:36:58 UTC

*** This bug has been marked as a duplicate of bug 657968 ***