Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-28863

Published: 21 March 2024

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

Priority

Medium

Status

Package Release Status
node-tar
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal Needed

jammy Needed

mantic Needed

noble Needs triage

trusty Not vulnerable
(code not present)
upstream
Released (6.1.13+~cs7.0.5-2)
xenial Not vulnerable
(code not present)