tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
[
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "src/cbang/os/SystemUtilities.cpp",
"function": "getMaxFiles"
},
"id": "CVE-2020-15908-43bbb2bd",
"deprecated": false,
"source": "https://github.com/cauldrondevelopmentllc/cbang/commit/33fcfc2b3ed2195a423606a264718e31e6b3903f",
"digest": {
"function_hash": "61334291877176663460830981579887394704",
"length": 330.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "src/cbang/tar/TarFileReader.cpp",
"function": "TarFileReader::extract"
},
"id": "CVE-2020-15908-5941743f",
"deprecated": false,
"source": "https://github.com/cauldrondevelopmentllc/cbang/commit/1c1dba62bd3e6fa9d0d0c0aa21926043b75382c7",
"digest": {
"function_hash": "330291312336699062807119318044419557734",
"length": 371.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "src/cbang/os/SystemUtilities.cpp",
"function": "setMaxFiles"
},
"id": "CVE-2020-15908-60461297",
"deprecated": false,
"source": "https://github.com/cauldrondevelopmentllc/cbang/commit/33fcfc2b3ed2195a423606a264718e31e6b3903f",
"digest": {
"function_hash": "134265113046046800593751689400312785263",
"length": 393.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "src/cbang/os/SystemUtilities.cpp"
},
"id": "CVE-2020-15908-93a2fad5",
"deprecated": false,
"source": "https://github.com/cauldrondevelopmentllc/cbang/commit/33fcfc2b3ed2195a423606a264718e31e6b3903f",
"digest": {
"line_hashes": [
"93222263366217280585838268728646987831",
"117214976741407514925125056241519894051",
"20328710960668083856589233009977652062",
"116025860981655107849480347871051534106",
"333468369182229158366934871405635368184",
"305312696882548822215394525676486505271",
"20328710960668083856589233009977652062",
"116025860981655107849480347871051534106"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "src/cbang/tar/TarFileReader.cpp"
},
"id": "CVE-2020-15908-987c4292",
"deprecated": false,
"source": "https://github.com/cauldrondevelopmentllc/cbang/commit/1c1dba62bd3e6fa9d0d0c0aa21926043b75382c7",
"digest": {
"line_hashes": [
"42323268789285406099917393496897498123",
"47861095226362428319389377121679713277",
"84378934578530421915437068660492534071",
"173004692445328327383613338185261069104",
"292874264989561364870479856867659474619",
"73885368114660467223094850905399786686"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15908.json"