Listen to this Post
The vulnerability in the Node.js `tar` library (version 7.5.1) occurs when using the `.t` or `.list` method with the `{ sync: true }` option. When a tar archive is read synchronously, the library initially checks the file’s size. If an attacker truncates the file to a smaller size on disk after this check but before the specific entry is read, the library’s internal buffer is not properly reinitialized. This causes the function responsible for reading the entry’s data to return chunks of uninitialized memory from its internal pool, which was allocated based on the original, larger file size. The memory is exposed to user code via the `onReadEntry` event handler. The specific condition for exploitation is that the truncation must occur precisely at the boundary between a tar header block and its subsequent data block. If the file is truncated to a size larger than the default `maxReadSize` of 16KB, the vulnerability instead triggers an infinite loop, causing a Denial-of-Service.
Platform: Node.js `tar`
Version: 7.5.1
Vulnerability: Information Disclosure
Severity: Critical
date: 2024
Prediction: 2024-10-15
What Undercode Say:
Simulating file truncation during read
$ node -e "
const tar = require('tar');
const fs = require('fs');
// Vulnerable code snippet
tar.t({
sync: true,
file: 'malicious.tar',
onReadEntry: (entry) => entry.on('data', (chunk) => {
// This chunk may contain uninitialized memory
console.log(chunk);
})
});
"
// Proof of Concept: Attacker truncates file
const fs = require('fs');
setInterval(() => {
fs.truncateSync('target.tar', 600); // Truncate to specific boundary
}, 10);
How Exploit:
An attacker must truncate a tar file being processed by the vulnerable library at the precise boundary between a header and its data block. This race condition causes the library to return uninitialized heap memory containing sensitive data like passwords, keys, or file contents from the process’s memory.
Protection from this CVE:
Upgrade `tar` library to version 7.5.2 or later. Avoid using `{ sync: true }` option. Use `tar.extract()` method instead. Implement file integrity checks.
Impact:
Information disclosure of process memory, potential exposure of secrets, Denial-of-Service via infinite loop.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

