perl-Archive-Tar-2.38-6.el9_8.1
エラータID: AXSA:2026-1439:02
リリース日:
2026/08/04 Tuesday - 15:48
題名:
perl-Archive-Tar-2.38-6.el9_8.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- perl-Archive-Tar には、パストラバーサル攻撃を許容してしまう
問題があるため、ローカルの攻撃者により、巧妙に細工された tar
ファイルを介して、情報の漏洩、データ破壊、およびサービス拒否
攻撃を可能とする脆弱性が存在します。(CVE-2026-42496)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
追加情報:
N/A
ダウンロード:
SRPMS
- perl-Archive-Tar-2.38-6.el9_8.1.src.rpm
MD5: 014531b23571d407c56edf7856f48028
SHA-256: eae673128e9c915975cb30f563846aaa3fa622c4bdb1d36bb732ff5ea4c4bd19
Size: 77.23 kB
Asianux Server 9 for x86_64
- perl-Archive-Tar-2.38-6.el9_8.1.noarch.rpm
MD5: 88bf19f60407a2a8ae4377fa10e567bb
SHA-256: 5223738c171b2fb64e75dd2c05898336808569667009d880c46afaf9cbc0c8e1
Size: 74.71 kB