VDB
DEBIAN-CVE-2018-12015
DEBIAN-CVE-2018-12015
PUBLISHED
CVSS 7.5 HIGH
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | perl | 0, 0, 0 |
| Debian:12 | perl | 0, 0, 0 |
| Debian:13 | perl | 0, 0, 0 |
| Debian:14 | perl | 0, 0, 0 |
Exploit Intelligence
- TestCommand.yaml (github-poc)
Timeline
- Jun 7, 2018 CVE Published
- Apr 28, 2026 CVE Updated