漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Vulnerability Description
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
未捕获的异常
Vulnerability Title
isaacs node-tar 异常处理不当漏洞
Vulnerability Description
isaacs node-tar是isaacs个人开发者开源的一款用于文件压缩/解压缩的软件包。 isaacs node-tar 7.5.17之前版本存在异常处理不当漏洞,该漏洞源于未从PAX路径和linkpath记录中剥离NUL字节,允许恶意构造的归档文件通过值传递给fs.lstat或fs.open,导致进程因未捕获异常而终止。
CVSS Information
N/A
Vulnerability Type
N/A