PT-2021-4597 · Unknown+8 · Archive Tar+8
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Archive Tar versions 1.4.11 and earlier
Description
The vulnerability in the Archive Tar library's Tar.php file is related to improper link resolution, allowing an attacker to impact data integrity through directory traversal due to inadequate checking of symbolic links.
Recommendations
For Archive Tar versions 1.4.11 and earlier, update to version 1.4.13 to resolve the issue. As a temporary workaround, consider restricting write operations to prevent directory traversal until the update is applied.
Exploit
Fix
DoS
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Archive Tar
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu