Path traversal in Perl - CVE-2018-12015

 

Path traversal in Perl - CVE-2018-12015

Published: June 8, 2018 / Updated: June 8, 2018


Vulnerability identifier: #VU13236
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12015
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into extracting a specially crafted tar archive containing a file and a symbolic link (symlink) with the same name, create a file outside of the current working directory, bypass a directory-traversal protection mechanism and create or overwrite files with the privileges of the target user.


Affected software

Perl
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
perl (Alpine package)
perl-Archive-Tar
Dynamic System Analysis (DSA) Preboot

How to mitigate CVE-2018-12015

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

perl (Alpine package) - update to 5.24.4-r1
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
perl-Archive-Tar - addressed in versions 2.28-1.fc27, 2.28-1.fc28

External References

Related Security Bulletins