CVE-2019-13173
Summary
| CVE | CVE-2019-13173 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-02 20:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:1907-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Overview |
MISC |
www.npmjs.com |
Patch, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:1846-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| USN-4123-1: npm/fstream vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Clobber a Link if it's in the way of a File · npm/fstream@6a77d2f · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981772 Nodejs (npm) Security Update for fstream (GHSA-xf7w-r453-m56c)