Description
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4226-1 | perl security update |
EUVD |
EUVD-2018-4007 | In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name. |
Ubuntu USN |
USN-3684-1 | Perl vulnerability |
Ubuntu USN |
USN-3684-2 | Perl vulnerability |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apple
Subscribe
Mac Os X
Subscribe
Archive\
Subscribe
\
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Netapp
Subscribe
Data Ontap Edge
Subscribe
Oncommand Workflow Automation
Subscribe
Snap Creator Framework
Subscribe
Snapdrive
Subscribe
Perl
Subscribe
Perl
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:24:03.584Z
Reserved: 2018-06-07T00:00:00.000Z
Link: CVE-2018-12015
No data.
Status : Modified
Published: 2018-06-07T13:29:00.240
Modified: 2024-11-21T03:44:24.850
Link: CVE-2018-12015
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN