Insecure session management In node-fstream
Description
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.0.12 | ||
debian 11 | 1.0.12-1 | ||
debian 12 | 1.0.12-1 | ||
debian 13 | 1.0.12-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.