6.4
CVSSv2

CVE-2019-13173

Published: 02/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

fstream prior to 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fstream project fstream

Vendor Advisories

Debian Bug report logs - #931408 node-fstream: CVE-2019-13173 Package: src:node-fstream; Maintainer for src:node-fstream is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 4 Jul 2019 09:15:02 UTC Severity: important Tags: ...
npm/fstream could be made to overwrite files ...