We found results for “”
CVE-2018-12015
Good to know:
Date: June 7, 2018
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Language: Perl
Severity Score
Related Resources (17)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version perl - 5.30.3;m2-perl - no_fix;perl-threaded - 5.26.0;git - 2.7.4;git - 2.15.0;git - 2.27.0;GitForWindows - 2.27.0-rc0;perl-archive-tar - 2.32;StrawberryPerl - 5.28.0.1;PortableGit - no_fix;git-bash - 2.24.0;StrawberryPerlPortable64 - no_fix;Cygwin - 2.2.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


