CVE-2021-32610: High severity archive::tar vulnerability
In ArchiveTar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-32610?
CVE-2021-32610 is a vulnerability in Archive_Tar before version 1.4.14 that allows symlinks to refer to targets outside of the extracted archive.
What is the severity of CVE-2021-32610?
The severity of CVE-2021-32610 is high with a CVSS score of 7.1.
Which software is affected by CVE-2021-32610?
Php Archive Tar version up to exclusive 1.4.14, Debian Debian Linux 9.0, Fedoraproject Fedora 33, Fedoraproject Fedora 34, and Fedoraproject Fedora 35 are affected by CVE-2021-32610.
How can I fix CVE-2021-32610?
To fix CVE-2021-32610, update to version 1.4.14 of Archive_Tar.
Where can I find more information about CVE-2021-32610?
You can find more information about CVE-2021-32610 on the following links: [Link 1](https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755), [Link 2](https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f), [Link 3](https://github.com/pear/Archive_Tar/releases/tag/1.4.14).