Symlink Vulnerability in Archive_Tar Affects PEAR
CVE-2021-32610
7.1HIGH
What is CVE-2021-32610?
In versions of Archive_Tar prior to 1.4.14, a vulnerability exists where symbolic links can point to targets that lie outside of the extracted archive. This flaw could allow unauthorized access to sensitive files by manipulating the extraction process if the attacker controls the contents of the archive. It is essential to update to version 1.4.14 or later to mitigate this risk.