Directory Traversal Vulnerability in Perl's Archive::Tar Module
CVE-2018-12015
7.5HIGH
Summary
The Archive::Tar module in Perl versions up to 5.26.2 has a vulnerability that allows attackers to exploit a directory traversal flaw. This vulnerability permits malicious actors to bypass the intended directory traversal protections. By crafting an archive that contains both a symlink and a regular file with the same name, an attacker can overwrite arbitrary files on the server. This capability poses significant security risks, enabling potential unauthorized access and manipulation of sensitive files within the affected systems.
References
EPSS Score
38% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved