perl-Archive-Tar-2.30-2.el8_10
エラータID: AXSA:2026-1104:01
リリース日:
2026/06/30 Tuesday - 17:38
題名:
perl-Archive-Tar-2.30-2.el8_10
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- perl-Archive-Tar には、パストラバーサル攻撃を許容してしまう
問題があるため、ローカルの攻撃者により、巧妙に細工された tar
ファイルを介して、情報の漏洩、データ破壊、およびサービス拒否
攻撃を可能とする脆弱性が存在します。(CVE-2026-42496)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
追加情報:
N/A
ダウンロード:
SRPMS
- perl-Archive-Tar-2.30-2.el8_10.src.rpm
MD5: eb0d87d6f7d24befb4fcd82656f4c52a
SHA-256: 51a4fc168e640ed649719b0b02892c61ff2566faeb0b11d0e62853fba19fb001
Size: 82.33 kB
Asianux Server 8 for x86_64
- perl-Archive-Tar-2.30-2.el8_10.noarch.rpm
MD5: eb6a3b54914b42b1ebb48f15efc653c8
SHA-256: 2f5c2621bbcc0e7e3f0d8414590d1526f562d66997b7d729d77217d7dd86c8e8
Size: 78.39 kB