First published: Tue Aug 10 2021(Updated: )
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tar Project Tar | <0.4.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38511 is a vulnerability in the tar crate for Rust, allowing arbitrary directory creation through symlink traversal during extraction.
The severity of CVE-2021-38511 is high, with a CVSS score of 7.5.
CVE-2021-38511 affects the Tar Project Tar software version up to, but excluding, 0.4.36.
To fix CVE-2021-38511, update the tar crate for Rust to version 0.4.36 or later.
The Common Weakness Enumeration (CWE) ID associated with CVE-2021-38511 is 59.