VDB
Sign up
MEDIUM5.3

GHSA-hpxr-w9w7-g4gv

stereoscope vulnerable to tar path traversal when processing OCI tar archives

Quick fix

GHSA-hpxr-w9w7-g4gv — github.com/anchore/stereoscope: upgrade to the fixed version with the command below.

go get github.com/anchore/stereoscope@v0.0.1

Details

### Impact It is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory. Specifically, use of `github.com/anchore/stereoscope/pkg/file.UntarToDirectory()` function, the `github.com/anchore/stereoscope/pkg/image/oci.TarballImageProvider` struct, or the higher level `github.com/anchore/stereoscope/pkg/image.Image.Read()` function express this vulnerability.

### Patches Patched in v0.0.1

### Workarounds If you are using the OCI archive as input into stereoscope then you can switch to using an [OCI layout](https://github.com/opencontainers/image-spec/blob/main/image-layout.md) by unarchiving the tar archive and provide the unarchived directory to stereoscope.

### References - Patch PR https://github.com/anchore/stereoscope/pull/214

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/anchore/stereoscope
Introduced in: 0Fixed in: 0.0.1
Fixgo get github.com/anchore/stereoscope@v0.0.1

References