CVE-2021-36193
published 2022-02-02CVE-2021-36193: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code…
PriorityP343high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.82%
53.0th percentile
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal_core | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 5.0.0 – 5.0.4 | — |
| fortinet | fortiadc | 5.1.0 – 5.1.7 | — |
| fortinet | fortiadc | 5.2.0 – 5.2.8 | — |
| fortinet | fortiadc | 5.3.0 – 5.3.7 | — |
| fortinet | fortiadc | 5.4.0 – 5.4.5 | — |
| fortinet | fortiadc | 6.0.0 – 6.0.4 | — |
| fortinet | fortiadc | 6.1.0 – 6.1.6 | — |
| fortinet | fortiadc | 6.2.0 – 6.2.2 | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | 4.4.0 – 4.4.2 | — |
| fortinet | fortiddos | 5.3.0 – 5.3.2 | — |
| fortinet | fortiddos | 5.4.0 – 5.4.3 | — |
| fortinet | fortiddos | 5.5.0 – 5.5.1 | — |
| fortinet | fortiddos | 5.6.0 – 5.6.1 | — |
| fortinet | fortiddos-cm | — | — |
| fortinet | fortiddos-cm | — | — |
| fortinet | fortiddos-cm | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
ghsa7.5HIGH
cisa7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xfch-762x-q3v9: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6
ghsa_unreviewed·2022-02-08
CVE-2021-36193 [HIGH] CWE-121 GHSA-xfch-762x-q3v9: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
GHSA
Directory Traversal in Archive_Tar
ghsa·2021-08-09·CVSS 7.5
CVE-2021-32610 [HIGH] CWE-59 Directory Traversal in Archive_Tar
Directory Traversal in Archive_Tar
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CISA
PEAR Archive_Tar Improper Link Resolution Vulnerability
cisa·2022-08-25·CVSS 7.5
CVE-2020-36193 [HIGH] CWE-22 PEAR Archive_Tar Improper Link Resolution Vulnerability
Vulnerability: PEAR Archive_Tar Improper Link Resolution Vulnerability
Affected: PEAR Archive_Tar
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Required Action: Apply updates per vendor instructions.
Notes: https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916, https://www.drupal.org/sa-core-2021-001, https://access.redhat.com/security/cve/cve-2020-36193; https://nvd.nist.gov/vuln/detail/CVE-2020-36193
Remediation Due Date: 2022-09-15
Fortinet
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...
vendor_fortinet·2022-02-02·CVSS 6.7
CVE-2021-36193 [MEDIUM] CWE-121 Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...
FG-IR-21-132: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
CVEs: CVE-2021-36193
CWEs: CWE-121, CWE-787
CVSS: 6.7 (medium)
Affected products: FortiWeb
Red Hat
php-pear: Directory traversal vulnerability
vendor_redhat·2021-07-30·CVSS 7.5
CVE-2021-32610 [HIGH] CWE-22 php-pear: Directory traversal vulnerability
php-pear: Directory traversal vulnerability
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
Package: php-pear (Red Hat Enterprise Linux 6) - Out of support scope
Package: php-pear (Red Hat Enterprise Linux 7) - Out of support scope
Package: php:7.3/php-pear (Red Hat Enterprise Linux 8) - Will not fix
Package: php-pear (Red Hat Enterprise Linux 9) - Not affected
Package: rh-php73-php-pear (Red Hat Software Collections) - Will not fix
Drupal
Drupal core - Critical - Third-party libraries - SA-CORE-2021-001
vendor_drupal·2021-01-20·CVSS 7.5
CVE-2020-36193 [HIGH] Drupal core - Critical - Third-party libraries - SA-CORE-2021-001
Title: Drupal core - Critical - Third-party libraries - SA-CORE-2021-001
Vulnerability Type: Third-party libraries
Description: The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. For more information please see: CVE-2020-36193 Exploits may be possible if Drupal is configured to allow .tar , .tar.gz , .bz2 , or .tlz file uploads and processes them.
Solution: Install the latest version: If you are using Drupal 9.1, update to Drupal 9.1.3 . If you are using Drupal 9.0, update to Drupal 9.0.11 . If you are using Drupal 8.9, update to Drupal 8.9.13 . If you are using Drupal 7, update to Drupal 7.78 . Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive security coverage. Disable uploads of .tar , .tar.gz , .bz2 ,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-02
Published