MGASA-2022-0103 - Updated nodejs-tar packages fix security vulnerability Publication date: 21 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0103.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-32803, CVE-2021-32804, CVE-2021-37701, CVE-2021-37712 Untrusted tar file to symlink into an arbitrary location allowing file overwrites. (CVE-2021-37712) Arbitrary file creation/overwrite and arbitrary code execution. (CVE-2021-37701) Arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. (CVE-2021-32803) Arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization (CVE-2021-32804) References: - https://bugs.mageia.org/show_bug.cgi?id=29656 - https://www.debian.org/security/2021/dsa-5008 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32803 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32804 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37701 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37712 SRPMS: - 8/core/nodejs-tar-6.0.5-1.1.mga8