archive-tar-new是Jos Boumans个人开发者的一个Perl模块,用于创建和内存操作tar文件。 archive-tar-new 3.10之前版本存在安全漏洞,该漏洞源于_read_tar函数读取tar标头中攻击者控制的条目大小字段时未设置上限,可能导致内存耗尽。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BINGOS | Archive::Tar | < 3.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BINGOS | Archive::Tar | 0 ~ 3.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42497 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths | |
| CVE-2026-42496 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targe |
No comments yet