Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-8860

Published: 23 January 2017

The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

From the Ubuntu Security Team

It was discovered that node-tar mishandled certain tar archives. An attacker could use this vulnerability to write arbitrary files to the filesystem.

Priority

Medium

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
node-tar
Launchpad, Ubuntu, Debian
artful Ignored
(end of life)
bionic Not vulnerable
(2.2.1-1)
cosmic Not vulnerable
(2.2.1-1)
disco Not vulnerable
(2.2.1-1)
eoan Not vulnerable
(2.2.1-1)
focal Not vulnerable
(2.2.1-1)
groovy Not vulnerable
(2.2.1-1)
hirsute Not vulnerable
(2.2.1-1)
impish Not vulnerable
(2.2.1-1)
jammy Not vulnerable
(2.2.1-1)
precise Ignored
(end of life)
trusty
Released (0.1.18-1ubuntu0.1~esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (2.0.0)
wily Ignored
(end of life)
xenial
Released (1.0.3-2ubuntu0.1~esm1)
Available with Ubuntu Pro
yakkety Ignored
(end of life)
zesty Ignored
(end of life)
Patches:
upstream: https://github.com/npm/node-tar/commit/a5337a6cd58a2d800fc03b3781a25751cf459f28
upstream: https://github.com/npm/node-tar/issues/54
upstream: https://github.com/npm/node-tar/pull/56
upstream: https://github.com/npm/node-tar/pull/56/commits/5e6356e0ca256cba659ff24d0befbfe753a04cb6
upstream: https://github.com/npm/node-tar/pull/56/commits/96355141e005fa192b4fd4c3134ec3bb824dfca8

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N