VDB

ALINUX2-SA-2019%3A0088

ALINUX2-SA-2019%3A0088 PUBLISHED CVSS 5.400000095367432 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-12015: In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

Risk Scores

CVSS 3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Affected Products

VendorProductVersions
Alibaba Cloudperl-Archive-Tar

Timeline

  • Oct 10, 2019 CVE Published
  • Oct 10, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›