CVE-2021-32610

Related Vulnerabilities: CVE-2021-32610  

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Description

The MITRE CVE dictionary describes this issue as:

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Additional Information

  • Bugzilla 1988558: CVE-2021-32610 php-pear: Directory traversal vulnerability
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • FAQ: Frequently asked questions about CVE-2021-32610