CVE-2021-32610
30.07.2021, 14:15
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
| Vendor | Product | Version |
|---|---|---|
| php | archive_tar | 𝑥 < 1.4.14 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| drupal7 |
| ||||||||||||||||||||||
| php-pear |
|
References