CVE-2018-20834

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
node-tar_projectnode-tar
𝑥
< 2.2.2
node-tar_projectnode-tar
3.0.0 ≤
𝑥
< 4.4.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-tar
bullseye (security)
6.0.5+ds1+~cs11.3.9-1+deb11u2
fixed
bullseye
6.0.5+ds1+~cs11.3.9-1+deb11u2
fixed
bookworm
6.1.13+~cs7.0.5-1
fixed
sid
6.2.1+~cs7.0.8-1
fixed
trixie
6.2.1+~cs7.0.8-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tar
disco
not-affected
cosmic
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected