tar-fs@0.1.2 vulnerabilities

filesystem bindings for tar-stream

  • latest version

    3.0.8

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    24 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the tar-fs package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Overwrite

    tar-fs is a filesystem bindings for tar-stream.

    Affected versions of this package are vulnerable to Arbitrary File Overwrite. An attacker can overwrite files on the system when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

    How to fix Arbitrary File Overwrite?

    Upgrade tar-fs to version 1.16.2 or higher.

    <1.16.2