Security Advisories (1)
CVE-2018-12015 (2018-06-12)

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

Changes for version 2.14

  • Fix roundtrip test when tar executable is absent

Documentation

a tar-like program written in perl
program that diffs an extracted archive against an unextracted one
Apply pattern matching to the contents of files in a tar archive

Modules

module for manipulations of tar archives
a subclass for in-memory extracted file from Archive::Tar

Provides

in lib/Archive/Tar/Constant.pm