VDB
Sign up
HIGH7.5

GHSA-j44m-qm6p-hp7m

Arbitrary File Overwrite in tar

Quick fix

GHSA-j44m-qm6p-hp7m — tar: upgrade to the fixed version with the command below.

npm install tar@4.4.2

Details

Versions of `tar` prior to 4.4.2 for 4.x and 2.2.2 for 2.x are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file.

## Recommendation

For tar 4.x, upgrade to version 4.4.2 or later. For tar 2.x, upgrade to version 2.2.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tar
Introduced in: 3.0.0Fixed in: 4.4.2
Fixnpm install tar@4.4.2
npm/tar
Introduced in: 0Fixed in: 2.2.2
Fixnpm install tar@2.2.2

References