GHSA-62jx-8vmh-4mcw
Dashboard / Vulnerabilities / GHSA-62jx-8vmh-4mcw
GHSA-62jx-8vmh-4mcw
Summary: Links in archive can create arbitrary directories
Details: When unpacking a tarball that contains a symlink the tar crate may create directories outside of the directory it's supposed to unpack into. The function errors when it's trying to create a file, but the folders are already created at this point.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-38511, https://github.com/alexcrichton/tar-rs/issues/238, https://github.com/alexcrichton/tar-rs/pull/259, https://github.com/alexcrichton/tar-rs, https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/tar/RUSTSEC-2021-0080.md, https://rustsec.org/advisories/RUSTSEC-2021-0080.html
Affected packages
Package
Name: tar
Purl: pkg:cargo/tar
Affected ranges
Type: SEMVER
Events:
