First published: Tue Jul 27 2021(Updated: )
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Archive Tar | <1.4.14 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32610 is a vulnerability in Archive_Tar before version 1.4.14 that allows symlinks to refer to targets outside of the extracted archive.
The severity of CVE-2021-32610 is high with a CVSS score of 7.1.
Php Archive Tar version up to exclusive 1.4.14, Debian Debian Linux 9.0, Fedoraproject Fedora 33, Fedoraproject Fedora 34, and Fedoraproject Fedora 35 are affected by CVE-2021-32610.
To fix CVE-2021-32610, update to version 1.4.14 of Archive_Tar.
You can find more information about CVE-2021-32610 on the following links: [Link 1](https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755), [Link 2](https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f), [Link 3](https://github.com/pear/Archive_Tar/releases/tag/1.4.14).