vendor:
tar-fs
by:
Ardayfio Samuel Nii Aryee
6.1
CVSS
HIGH
Arbitrary File Write/Overwrite
22
CWE
Product Name: tar-fs
Affected Version From: 3.0.0
Affected Version To: 3.0.0
Patch Exists: NO
Related CWE: CVE-2024-12905
CPE: tar-fs:3.0.0
Platforms Tested: Ubuntu
2024
tar-fs 3.0.0 – Arbitrary File Write/Overwrite
The exploit allows an attacker to write/overwrite arbitrary files on the system using the tar-fs 3.0.0 package. By running a specific command, two tar files are generated which can be uploaded sequentially to create a symlink and then write/overwrite the target file.
Mitigation:
Users should avoid running commands or scripts from untrusted sources. Additionally, it is recommended to regularly update software packages to the latest versions to prevent exploitation.