3.6
CVSSv2

CVE-2021-32610

Published: 30/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Archive_Tar prior to 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php archive tar

debian debian linux 9.0

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Synopsis Moderate: php:74 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the php:74 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security ...
Debian Bug report logs - #991541 php-pear: CVE-2021-32610: symbolic link path traversal Package: src:php-pear; Maintainer for src:php-pear is Debian PHP Maintainers <team+pkg-php@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Jul 2021 06:03:01 UTC Severity: grave Tags: securi ...
In Archive_Tar before 1414, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193 (CVE-2021-32610) ...
In Archive_Tar before 1414, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193 ...
In Archive_Tar before 1414, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193 ...