UbuntuUpdates.org

Package "node-fstream"

Name: node-fstream

Description:

Advanced filesystem streaming tools for Node.js

Latest version: 1.0.10-1ubuntu0.18.04.1
Release: bionic (18.04)
Level: security
Repository: universe
Homepage: https://github.com/npm/fstream

Links


Download "node-fstream"


Other versions of "node-fstream" in Bionic

Repository Area Version
base universe 1.0.10-1
updates universe 1.0.10-1ubuntu0.18.04.1

Changelog

Version: 1.0.10-1ubuntu0.18.04.1 2019-09-05 13:06:46 UTC

  node-fstream (1.0.10-1ubuntu0.18.04.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Arbitrary file overwrite via tarballs containing a
    hardlink
    - debian/patches/CVE-2019-13173.patch: Clobber a Link if it's in the way
      of a File
    - CVE-2019-13173

 -- Mike Salvatore <email address hidden> Tue, 27 Aug 2019 09:44:17 -0400

CVE-2019-13173 fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the syste



About   -   Send Feedback to @ubuntu_updates