Path traversal in NPM - CVE-2019-16777
Published: December 12, 2019 / Updated: February 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. The software fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the first binary. This only affects files in /usr/local/bin
A remote attacker can overwrite arbitrary files on the system.
Affected software
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Red Hat Software Collections
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
IBM VM Recovery Manager DR
IBM InfoSphere Information Server
How to mitigate CVE-2019-16777
IBM VM Recovery Manager DR - update to 1.5.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Path traversal in npm package for Node.js
- Red Hat update for nodejs:10 module
- Red Hat 8 update for nodejs:10
- Red Hat Software Collections security update for rh-nodejs12-nodejs
- Red Hat Software Collections update for rh-nodejs10-nodejs
- Red Hat Enterprise Linux 8 update for nodejs:12
- OpenSUSE Linux update for nodejs8
- Gentoo update for Node.js
- Multiple vulnerabilities in IBM VM Recovery Manager DR
- Multiple vulnerabilities in IBM InfoSphere Information Server