Junglewise Threat Intelligence

CVE-2019-13173: npm fstream arbitrary file overwrite in DirWriter

CVE-2019-13173 · Severity: low · CVSS 3 · Published 2019-05-30

Vendors: npm.

Executive brief

fstream is a widely-used Node.js library for streaming file operations, commonly used in build tools and package managers. A vulnerability in the DirWriter function allows attackers to overwrite arbitrary files on a system by crafting malicious tar archives containing hardlinks. This could lead to system compromise, data loss, or injection of malicious code into critical system files.

Technical details

The vulnerability exists in fstream versions prior to 1.0.12 in the DirWriter function's file extraction logic (CWE-59: Improper Link Resolution Before File Access). When extracting a tarball, if the archive contains both a hardlink to an existing system file and a regular file targeting the same destination, the function incorrectly overwrites the original system file with the tarball contents. The attack requires the attacker to control the tarball being extracted and the victim system to have the target file present. The fix removes the check that prevented overwriting hardlinks, replacing it with logic that clobbers hardlinks when needed (version 1.0.12+).

Affected products

  • npm fstream prior to 1.0.12

Timeline

  • 2019-05-30: disclosed
  • 2019-05-30: patched: fstream 1.0.12 released with fix

References