CVE-2021-38511Link Following in Project TAR

Severity
7.5HIGHNVD
EPSS
0.3%
top 43.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 10
Latest updateAug 25

Description

An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

crates.iognu/tar0.0.0-00.4.36+1
NVDtar_project/tar< 0.4.36

🔴Vulnerability Details

5
GHSA
Links in archive can create arbitrary directories2021-08-25
OSV
Links in archive can create arbitrary directories2021-08-25
OSV
CVE-2021-38511: An issue was discovered in the tar crate before 02021-08-10
CVEList
CVE-2021-38511: An issue was discovered in the tar crate before 02021-08-10
OSV
Links in archive can create arbitrary directories2021-07-19

📋Vendor Advisories

2
Debian
CVE-2021-38511: rust-tar - An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks a...2021
Red Hat
tar-crate: links in archive can create arbitrary directories2020-09-10
CVE-2021-38511 — Link Following in TAR Project TAR | cvebase