Executive brief
Node-tar is a popular Node.js library for reading and writing tar archives. An attacker can cause a denial of service by crafting a malicious tar file with excessively nested folder paths, which exhausts system memory and CPU resources, potentially crashing applications that use this library to extract untrusted archives.
Technical details
The vulnerability exists in the tar file parsing logic where there is no validation on the depth or count of nested folders that can be created during archive extraction. When processing a tar file with a path containing many nested directories (e.g., ./a/b/c/.../z/file.txt), node-tar recursively creates each folder without enforcing any limits on folder depth. An attacker can exploit this by providing a crafted tar archive with deeply nested paths, causing the extraction process to allocate excessive memory and consume CPU resources, ultimately leading to denial of service through heap memory exhaustion or process crash. The vulnerability affects node-tar versions ≤6.2.0 and was fixed in version 6.2.1 by introducing folder depth validation.
Affected products
- npm node-tar <=6.2.0
- npm tar <=6.2.0
Timeline
- 2024-03-21: disclosed
- 2024-03-21: patched: Fixed in version 6.2.1