5.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is given a local .tar.gz that is not recognized as a plugin-format bundle, APM probes whether it is a legacy --format apm bundle. On Python versions earlier than 3.12, that probe extracts untrusted tar members with raw tar.extractall() without rejecting Windows absolute member names such as D:/.... This vulnerability is fixed in 0.13.0.
References
Affected products
- ==< 0.13.0
Matching in nixpkgs
pkgs.wapm
Package manager for WebAssembly modules
pkgs.apmplanner2
Ground station software for autonomous vehicles
pkgs.ldapmonitor
Tool to monitor creation, deletion and changes to LDAP objects
pkgs.xf86videoapm
Alliance Promotion video driver for the Xorg X server
pkgs.xf86-video-apm
None
pkgs.snapmaker-luban
Snapmaker Luban is an easy-to-use 3-in-1 software tailor-made for Snapmaker machines
pkgs.xorg.xf86videoapm
None
pkgs.kdePackages.kapman
Kapman is a clone of the well known game Pac-Man
pkgs.haskellPackages.tmapmvar
A single-entity stateful Map in STM, similar to tmapchan
pkgs.python312Packages.elastic-apm
Python agent for the Elastic APM
pkgs.python313Packages.elastic-apm
Python agent for the Elastic APM
pkgs.python314Packages.elastic-apm
Python agent for the Elastic APM
pkgs.pkgsRocm.python3Packages.elastic-apm
Python agent for the Elastic APM
Package maintainers
-
@wucke13 Wucke <wucke13@gmail.com>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@K900 Ilya K. <me@0upti.me>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@simonkampe Simon Kämpe <simon.kampe+nix@gmail.com>
-
@lucperkins Luc Perkins <lucperkins@gmail.com>