Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nanotar 安全漏洞
Vulnerability Description
nanotar是UnJS开源的一个实用程序!。 nanotar 0.2.0及之前版本存在安全漏洞,该漏洞源于parseTar和parseTarGzip函数存在路径遍历,可能导致远程攻击者将任意文件写入预期提取目录之外。
CVSS Information
N/A
Vulnerability Type
N/A