Symlink Vulnerability in Archive_Tar Affects PEAR
CVE-2021-32610

7.1HIGH

Key Information:

Vendor

PHP

Vendor
CVE Published:
30 July 2021

What is CVE-2021-32610?

In versions of Archive_Tar prior to 1.4.14, a vulnerability exists where symbolic links can point to targets that lie outside of the extracted archive. This flaw could allow unauthorized access to sensitive files by manipulating the extraction process if the attacker controls the contents of the archive. It is essential to update to version 1.4.14 or later to mitigate this risk.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.