Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-32610

Опубликовано: 30 июл. 2021
Источник: debian
EPSS Средний

Описание

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7removedpackage
php-pearfixed1:1.10.13+submodules+notgz-1package
php-pearno-dsabullseyepackage
php-pearno-dsabusterpackage
php-pearno-dsastretchpackage

Примечания

  • https://www.drupal.org/sa-core-2021-004

  • https://pear.php.net/package/Archive_Tar/download/1.4.14/

  • https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f61ca26bf7d4 (1.4.14)

EPSS

Процентиль: 93%
0.11731
Средний

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 4 года назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.4
redhat
почти 4 года назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
nvd
почти 4 года назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

suse-cvrf
больше 2 лет назад

Security update for php8-pear

suse-cvrf
почти 3 года назад

Security update for php8-pear

EPSS

Процентиль: 93%
0.11731
Средний