Lucene search

K
osvGoogleOSV:GHSA-RPW6-9XFX-JVCX
HistoryApr 22, 2021 - 4:20 p.m.

Directory Traversal in Archive_Tar

2021-04-2216:20:36
Google
osv.dev
14

0.882 High

EPSS

Percentile

98.7%

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

:exclamation: Note:

There was an initial fix for this vulnerability made in version 1.4.12. That fix introduced a bug which was fixed in 1.4.13. Therefore we have set the first-patched-version to 1.4.13 which the earliest working version that avoids this vulnerability.

References