VDB
KO
HIGH

GHSA-hfg8-hc9c-6c3h

moby/go-archive: Crafted tar archive can write outside the extraction directory

Quick fix

GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive: upgrade to the fixed version with the command below.

go get github.com/moby/go-archive@v0.3.0

Details

### Summary The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination.

### Details The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so a links introduced by the archive can be followed out of the destination directory.

### Impact An attacker who controls the contents of archive can create or overwrite files at arbitrary paths writable by the extracting process.

### Workarounds Only extract trusted archives.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/moby/go-archive
Introduced in: 0 Fixed in: 0.3.0
Fix go get github.com/moby/go-archive@v0.3.0

References