Debian Patches
Status for node-tar-fs/3.0.9+~cs2.0.4-2
Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
---|---|---|---|---|---|---|
keep-test-with-tape.patch | keep test with tape | Yadd <yadd@debian.org> | not-needed | 2025-03-31 | ||
CVE-2025-59343.patch | expand check tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories. |
Mathias Buus <mathiasbuus@gmail.com> | not-needed | debian upstream | upstream, https://github.com/mafintosh/tar-fs/commit/0bd54cdf | 2025-09-25 |
All known versions for source package 'node-tar-fs'
- 3.0.9+~cs2.0.4-2 (forky, sid)
- 3.0.9+~cs2.0.4-1 (trixie)
- 2.1.3-0+deb12u1 (bookworm)