Vulnerability Description
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Archive Tar | < 1.4.14 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9PatchThird Party Advisory
- https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4fPatchThird Party Advisory
- https://github.com/pear/Archive_Tar/releases/tag/1.4.14Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/07/msg00023.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.drupal.org/sa-core-2021-004Third Party Advisory
- https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9PatchThird Party Advisory
- https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4fPatchThird Party Advisory
- https://github.com/pear/Archive_Tar/releases/tag/1.4.14Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/07/msg00023.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2021-32610?
CVE-2021-32610 is a vulnerability with a CVSS score of 7.1 (HIGH). In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
How severe is CVE-2021-32610?
CVE-2021-32610 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32610?
Check the references section above for vendor advisories and patch information. Affected products include: Php Archive Tar, Debian Debian Linux, Fedoraproject Fedora.