Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Vulnerability Description
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
isaacs node-tar 资源管理错误漏洞
Vulnerability Description
isaacs node-tar是isaacs个人开发者开源的一款用于文件压缩/解压缩的软件包。 isaacs node-tar 7.5.21之前版本存在资源管理错误漏洞,该漏洞源于filesFilter中的mapHas辅助函数递归处理归档条目路径时未限制路径段数量,特制的GNU L或PAX x长路径头可能导致未捕获的RangeError堆栈溢出,导致异步和流式Node.js消费者被终止,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A