Debian Patches

Status for node-tar-fs/3.0.9+~cs2.0.4-2

Patch Description Author Forwarded Bugs Origin Last update
keep-test-with-tape.patch keep test with tape Yadd <yadd@debian.org> not-needed 2025-03-31
CVE-2025-59343.patch expand check tar-fs provides filesystem bindings for tar-stream. Versions prior
to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation
bypass if the destination directory is predictable with a specific
tarball. This issue has been patched in version 3.1.1, 2.1.4, and
1.16.6. A workaround involves using the ignore option on non
files/directories.
Mathias Buus <mathiasbuus@gmail.com> not-needed debian upstream upstream, https://github.com/mafintosh/tar-fs/commit/0bd54cdf 2025-09-25

All known versions for source package 'node-tar-fs'

Links