CVE-2021-32610

CWE-59CWE-22Path Traversal11 documents8 sources
Severity
7.1HIGH
EPSS
3.0%
top 13.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateAug 9

Description

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDphp/archive_tar< 1.4.14
Packagistpear/archive_tar< 1.4.14
Packagistdrupal/core8.0.08.9.17+2
Debianphp-pear< 1:1.10.13+submodules+notgz-1+2

Also affects: Debian Linux 9.0, Fedora 33, 34, 35

Patches

🔴Vulnerability Details

5
GHSA
Directory Traversal in Archive_Tar2021-08-09
OSV
Directory Traversal in Archive_Tar2021-08-09
OSV
CVE-2021-32610: In Archive_Tar before 12021-07-30
CVEList
CVE-2021-32610: In Archive_Tar before 12021-07-27
OSV
CVE-2021-32610: The Drupal project uses the pear Archive\_Tar library, which has released a security update that impacts Drupal2021-07-21

📋Vendor Advisories

5
Ubuntu
PEAR vulnerability2021-08-04
Red Hat
php-pear: Directory traversal vulnerability2021-07-30
Ubuntu
PEAR vulnerability2021-07-29
Drupal
Drupal core - Critical - Drupal core - Critical - Third-party libraries - SA-CORE-2021-0042021-07-21
Debian
CVE-2021-32610: php-pear - In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extra...2021
CVE-2021-32610 (HIGH CVSS 7.1) | In Archive_Tar before 1.4.14 | cvebase.io