VDB

GCVE-110-MAGEIA-2022-103

GCVE-110-MAGEIA-2022-103
Advisory Published
Vulnetix · Advisory published March 21, 2022
Untrusted tar file to symlink into an arbitrary location allowing file overwrites. (CVE-2021-37712) Arbitrary file creation/overwrite and arbitrary code execution. (CVE-2021-37701) Arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. (CVE-2021-32803) Arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization (CVE-2021-32804)

Affected Products

VendorProductVersionsPlatforms
Mageiagcc10.4.0-3.mga8 (unaffected), 0 (affected)
Mageianodejs-tar0 (affected), 6.0.5-1.1.mga8 (unaffected), 0 (affected), 6.0.5-1.1.mga8 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›