Symlink Vulnerability in Archive_Tar Affects PEAR
CVE-2021-32610
7.1HIGH
Summary
In versions of Archive_Tar prior to 1.4.14, a vulnerability exists where symbolic links can point to targets that lie outside of the extracted archive. This flaw could allow unauthorized access to sensitive files by manipulating the extraction process if the attacker controls the contents of the archive. It is essential to update to version 1.4.14 or later to mitigate this risk.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved