blob: 3fe93a76ecc93db8e5b7cdd3558cf0c2c3d5cb48 [file] [log] [blame]
module = "github.com/openshift/source-to-image"
package = "github.com/openshift/source-to-image/pkg/tar"
description = """
Malicious Zip and Tar archives can be crafted that contain relative
file paths, such that arbitary files outside of the target directory
may be overwritten.
"""
cve = "CVE-2018-1103"
symbols = ["stiTar.ExtractTarStreamFromTarReader", "stiTar.extractLink", "New"]
published = "2021-04-14T12:00:00Z"
[[versions]]
fixed = "v1.1.10-0.20180427153919-f5cbcbc5cc6f"
[links]
commit = "https://github.com/openshift/source-to-image/commit/f5cbcbc5cc6f8cc2f479a7302443bea407a700cb"
context = ["https://snyk.io/research/zip-slip-vulnerability"]