CVE-2019-13173
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
02/07/2019
Last modified:
24/08/2020
Description
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fstream_project:fstream:*:*:*:*:*:node.js:*:* | 1.0.12 (excluding) |
To consult the complete list of CPE names with products and versions, see this page