Oval Definition:oval:com.ubuntu.bionic:def:2019131730000000
Revision Date:2019-07-02Version:1
Title:CVE-2019-13173 on Ubuntu 18.04 LTS (bionic) - low.
Description:fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable. It was discovered that npm/fstream incorrectly handled certain crafted tarballs. An attacker could use this vulnerability to write aritrary files to the filesystem.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-13173
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND node-fstream package in bionic was vulnerable but has been fixed (note: '1.0.10-1ubuntu0.18.04.1').
  • BACK