Symlink Vulnerability in Archive_Tar Affects PEAR
CVE-2021-32610

7.1HIGH

Key Information:

Vendor
PHP
Vendor
CVE Published:
30 July 2021

Summary

In versions of Archive_Tar prior to 1.4.14, a vulnerability exists where symbolic links can point to targets that lie outside of the extracted archive. This flaw could allow unauthorized access to sensitive files by manipulating the extraction process if the attacker controls the contents of the archive. It is essential to update to version 1.4.14 or later to mitigate this risk.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.