CVE-2019-13173 is an Arbitrary File Overwrite vulnerability affecting fstream before version 1.0.12, specifically within the fstream.DirWriter() function. This vulnerability allows an attacker to overwrite system files by crafting a malicious tarball containing a hardlink to an existing system file and a matching file within the archive. Rated 7.5 HIGH, it has a low attack complexity and requires no user interaction, but only impacts integrity (I:H) with no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.12CPE matchmatch criteria | cpe:2.3:a:fstream_project:fstream:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.