Problem Description:
Flaws in libarchive's handling of symlinks and hard links
allow overwriting files outside the extraction directory,
or permission changes to a directory outside the extraction
directory.
Impact:
An attacker who can control freebsd-update's or portsnap's
input to tar(1) can change file content or permissions on
files outside of the update tool's working sandbox.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center