CVE-2018-12015: High severity Apple macOS Mojave vulnerability
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Other sources
Perl. Multiple issues in Perl were addressed in this update.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-6203
- CVE-2019-8531
- CVE-2019-8538
- CVE-2019-8534
- CVE-2019-8555
- CVE-2019-6239
- CVE-2019-8516
- CVE-2019-8552
- CVE-2019-8511
- CVE-2019-8542
- CVE-2019-8522
- CVE-2019-8550
- CVE-2019-8777
- CVE-2019-8565
- CVE-2019-8521
- CVE-2019-8906
- CVE-2019-8519
- CVE-2019-8533
- CVE-2019-8545
- CVE-2019-8504
- CVE-2019-8529
- CVE-2018-4448
- CVE-2019-5608
- CVE-2019-8527
- CVE-2019-8528
- CVE-2019-8508
- CVE-2019-8514
- CVE-2019-8540
- CVE-2019-7293
- CVE-2019-6207
- CVE-2019-8510
- CVE-2019-8547
- CVE-2019-8525
- CVE-2018-4433
- CVE-2019-8642
- CVE-2019-8645
- CVE-2019-8546
- CVE-2019-8579
- CVE-2019-8537
- CVE-2019-8561
- CVE-2018-12015
- CVE-2018-18311
- CVE-2018-18313
- CVE-2019-8549
- CVE-2019-8507
- CVE-2019-8618
- CVE-2019-8526
- CVE-2019-8520
- CVE-2019-8502
- CVE-2019-8513
- CVE-2019-8569
- CVE-2019-8517
- CVE-2019-8564
- CVE-2019-8612
- CVE-2019-8567
- CVE-2019-6238
- CVE-2019-8530
Frequently Asked Questions
What is the vulnerability ID for this Perl vulnerability?
The vulnerability ID for this Perl vulnerability is CVE-2018-12015.
How does the vulnerability affect Perl?
The vulnerability allows remote attackers to bypass a directory-traversal protection mechanism and overwrite arbitrary files.
Which software versions are affected by this vulnerability?
The affected software versions include Perl through 5.26.2 and Archive::Tar up to version 2.28.
What is the severity level of this vulnerability?
The severity level of this vulnerability is high, with a CVSS score of 7.5.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [1] [2] [3]