ALAS2-2019-1330

Related Vulnerabilities: CVE-2018-12015  

It was found that the Archive::Tar module did not properly sanitize symbolic links when extracting tar archives. An attacker, able to provide a specially crafted archive for processing, could use this flaw to write or overwrite arbitrary files in the context of the Perl interpreter.(CVE-2018-12015)

ALAS2-2019-1330


Amazon Linux 2 Security Advisory: ALAS-2019-1330
Advisory Release Date: 2019-10-21 18:01 Pacific
Advisory Updated Date: 2019-10-23 23:53 Pacific
Severity: Medium
References: CVE-2018-12015 

Issue Overview:

It was found that the Archive::Tar module did not properly sanitize symbolic links when extracting tar archives. An attacker, able to provide a specially crafted archive for processing, could use this flaw to write or overwrite arbitrary files in the context of the Perl interpreter.(CVE-2018-12015)


Affected Packages:

perl-Archive-Tar


Issue Correction:
Run yum update perl-Archive-Tar to update your system.

New Packages:
noarch:
    perl-Archive-Tar-1.92-3.amzn2.noarch

src:
    perl-Archive-Tar-1.92-3.amzn2.src