CVE-2018-12015

Name
CVE-2018-12015
Description
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900834
Third Party Advisory http://www.securitytracker.com/id/1041048
Third Party Advisory https://www.debian.org/security/2018/dsa-4226
Third Party Advisory http://www.securityfocus.com/bid/104423
Third Party Advisory https://usn.ubuntu.com/3684-2/
Third Party Advisory https://usn.ubuntu.com/3684-1/
Patch https://security.netapp.com/advisory/ntap-20180927-0001/
Third Party Advisory https://support.apple.com/kb/HT209600
Mailing List https://seclists.org/bugtraq/2019/Mar/42
Mailing List http://seclists.org/fulldisclosure/2019/Mar/49
REDHAT https://access.redhat.com/errata/RHSA-2019:2097
MISC https://www.oracle.com/security-alerts/cpujul2020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* ubuntu_linux == None == 18.04
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* ubuntu_linux == None == 17.10
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* ubuntu_linux == None == 16.04
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* ubuntu_linux == None == 14.04
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* ubuntu_linux == None == 12.04

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
perl edge-main 5.26.2-r1 None fixed
perl 3.22-main 5.26.2-r1 None fixed
perl 3.21-main 5.26.2-r1 None fixed
perl 3.20-main 5.26.2-r1 None fixed
perl 3.19-main 5.26.2-r1 None fixed
perl 3.18-main 5.26.2-r1 None fixed
perl 3.17-main 5.26.2-r1 None fixed
perl 3.12-main 5.26.2-r1 None fixed
perl 3.11-main 5.26.2-r1 None fixed
perl 3.10-main 5.26.2-r1 None fixed