CVE-2018-12015
published 2018-06-07CVE-2018-12015: In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files…
PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
7.34%
93.7th percentile
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.14.4 | 10.14.4 |
| apple | macos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perl | < perl 5.26.2-6 (bookworm) | perl 5.26.2-6 (bookworm) |
| perl | perl | <= 5.26.2 | — |
| perl | perl | >= 0 < 5.26.2-6 | 5.26.2-6 |
| perl | perl | >= 0 < 5.26.2-6 | 5.26.2-6 |
| perl | perl | >= 0 < 5.26.2-6 | 5.26.2-6 |
| perl | perl | >= 0 < 5.26.2-6 | 5.26.2-6 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44r9-882w-xw5m: In Perl through 5
ghsa_unreviewed·2022-05-13
CVE-2018-12015 [HIGH] CWE-59 GHSA-44r9-882w-xw5m: In Perl through 5
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
OSV
CVE-2018-12015: In Perl through 5
osv·2018-06-07·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015: In Perl through 5
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Apple
CVE-2018-12015: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
vendor_apple·2019-03-25·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Product: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
CVE: CVE-2018-12015
Component: Perl
Impact: Multiple issues in Perl
Description: Multiple issues in Perl were addressed in this update.
Ubuntu
Perl vulnerability
vendor_ubuntu·2018-06-13
CVE-2018-12015 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to overwrite arbitrary files if it received
a specially crafted archive file.
It was discovered that Perl incorrectly handled certain archive files.
An attacker could possibly use this to overwrite arbitrary files.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Perl vulnerability
vendor_ubuntu·2018-06-13
CVE-2018-12015 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to overwrite arbitrary files if it received
a specially crafted archive file.
USN-3684-1 fixed a vulnerability in perl. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Perl incorrectly handled certain archive files.
An attacker could possibly use this to overwrite arbitrary files.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: Directory traversal in Archive::Tar
vendor_redhat·2018-06-07·CVSS 7.5
CVE-2018-12015 [HIGH] CWE-22 perl: Directory traversal in Archive::Tar
perl: Directory traversal in Archive::Tar
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
It was found that the Archive::Tar module did not properly sanitize symbolic links when extracting tar archives. An attacker, able to provide a specially crafted archive for processing, could use this flaw to write or overwrite arbitrary files in the context of the Perl interpreter.
Package: perl-Archive-Tar (Red Hat Enterprise Linux 5) - Will not fix
Package: perl (Red Hat Enterprise Linux 6) - Will not fix
Package: perl-Archive-Tar (Red Hat Enterprise Linux 8) - Not affected
Package: rh-perl520-perl-Archive-
Debian
CVE-2018-12015: perl - In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypas...
vendor_debian·2018·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015: perl - In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypas...
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Scope: local
bookworm: resolved (fixed in 5.26.2-6)
bullseye: resolved (fixed in 5.26.2-6)
forky: resolved (fixed in 5.26.2-6)
sid: resolved (fixed in 5.26.2-6)
trixie: resolved (fixed in 5.26.2-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
bugzilla·2018-06-14·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1588760,1591205
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart a
Bugzilla
CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
bugzilla·2018-06-14·CVSS 6.8
CVE-2018-10860 [MEDIUM] CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
Archive::Zip does not protect against symlinks or '..' path traversals. Attacks similar to CVE-2007-4829 or CVE-2018-12015 also affect Archive::Zip.
Discussion:
Archive::Zip has never been part of upstream Perl release:
$ corelist Archive::Zip
Data for 2018-04-14
Archive::Zip was not in CORE (or so I think)
It's an independent project .
---
Note: summary edited for clarification.
---
Acknowledgments:
Name: Doran Moppert (Red Hat)
---
Created perl-Archive-Zip tracking bugs for this issue:
Affects: fedora-all [bug 1596132]
---
Upstream fix:
https://github.com/redhotpenguin/perl-Archive-Zip/commit/95e1df86327
---
perl-Archive-Zip-1.59-6.fc27 has been pushed to the Fedora 27 stable repository. If problems st
Bugzilla
CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
bugzilla·2018-06-07·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
CVE-2018-12015 perl-Archive-Tar: perl: Directory traversal in Archive::Tar [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2018-12015 perl: Directory traversal in Archive::Tar
bugzilla·2018-06-07·CVSS 7.5
CVE-2018-12015 [HIGH] CVE-2018-12015 perl: Directory traversal in Archive::Tar
CVE-2018-12015 perl: Directory traversal in Archive::Tar
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900834
Discussion:
Created perl tracking bugs for this issue:
Affects: fedora-all [bug 1588761]
---
Please note that all Fedoras, RHSCLs and RHEL ≥ 7 do not provide Archive::Tar module by perl source package, but by perl-Archive-Tar source package.
---
(In reply to Petr Pisar from comment #2)
> Please note that all Fedoras, RHSCLs and RHEL ≥ 7 do not provide
> Archive::Tar module by perl source package, but by perl-Archive-Tar sou
http://seclists.org/fulldisclosure/2019/Mar/49http://www.securityfocus.com/bid/104423http://www.securitytracker.com/id/1041048https://access.redhat.com/errata/RHSA-2019:2097https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900834https://seclists.org/bugtraq/2019/Mar/42https://security.netapp.com/advisory/ntap-20180927-0001/https://support.apple.com/kb/HT209600https://usn.ubuntu.com/3684-1/https://usn.ubuntu.com/3684-2/https://www.debian.org/security/2018/dsa-4226https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://seclists.org/fulldisclosure/2019/Mar/49http://www.securityfocus.com/bid/104423http://www.securitytracker.com/id/1041048https://access.redhat.com/errata/RHSA-2019:2097https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900834https://seclists.org/bugtraq/2019/Mar/42https://security.netapp.com/advisory/ntap-20180927-0001/https://support.apple.com/kb/HT209600https://usn.ubuntu.com/3684-1/https://usn.ubuntu.com/3684-2/https://www.debian.org/security/2018/dsa-4226https://www.oracle.com/security-alerts/cpujul2020.html
2018-06-07
Published