CVE-2020-36193: PEAR Archive_Tar Improper Link Resolution Vulnerability
A flaw was found in the ArchiveTar package. ArchiveTar could allow a remote attacker to traverse directories on the system caused by inadequate checking of symbolic links. An attacker could send a specially-crafted URL request to the Tar.php script containing "dot dot" sequences (/../) to modify arbitrary files on the system.
Other sources
Allows write operations with Directory Traversal due to inadequate checking of symbolic links
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/php-pearto a version that resolves this vulnerability.Fixed in 1:1.9.4-23.el7_9 - Upgrade
Upgrade
debian/php-pearto a version that resolves this vulnerability.Fixed in 1:1.10.6+submodules+notgz-1.1+deb10u2Fixed in 1:1.10.12+submodules+notgz+20210212-1Fixed in 1:1.10.13+submodules+notgz+2022032202-2 - Upgrade
Upgrade
debian/php-pearto a version that resolves this vulnerability.Fixed in 1:1.10.12+submodules+notgz+20210212-1Fixed in 1:1.10.6+submodules+notgz-1.1+deb10u2 - Upgrade
Upgrade
redhat/Archive_Tarto a version that resolves this vulnerability.Fixed in 1.4.12
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-36193?
CVE-2020-36193 is a vulnerability in PEAR Archive_Tar that allows write operations with directory traversal due to inadequate checking of symbolic links.
How does CVE-2020-36193 impact PEAR Archive_Tar?
CVE-2020-36193 allows attackers to perform directory traversal and potentially write files outside of the intended directory.
What is the severity level of CVE-2020-36193?
CVE-2020-36193 has a severity level of 7.5 (High).
How can I fix CVE-2020-36193 in PEAR Archive_Tar?
To fix CVE-2020-36193, upgrade to version 1.4.12 of PEAR Archive_Tar.
Are there any references related to CVE-2020-36193?
Yes, you can find references related to CVE-2020-36193 at the following links: [Link 1](https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916), [Link 2](https://www.drupal.org/sa-core-2021-001).