Oval Definition:oval:com.ubuntu.xenial:def:2019131730000000
Revision Date:2019-07-02Version:1
Title:CVE-2019-13173 on Ubuntu 16.04 LTS (xenial) - low.
Description:fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable. It was discovered that npm/fstream incorrectly handled certain crafted tarballs. An attacker could use this vulnerability to write aritrary files to the filesystem.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-13173
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND node-fstream package in xenial is affected and needs fixing.
  • BACK