PEAR Archive_Tar Improper Link Resolution
What to do
Apply updates per vendor instructions.
CISA deadline 2022-09-15 · passed 3 years 11 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA
What happened
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Who is affected
PEAR Archive_Tar. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.
Weakness class: CWE-22, CWE-59.
Timeline
- Added to CISA KEVExploitation in the wild confirmed by CISA
- CISA remediation deadlinepassed 3 years 11 months ago
Sources
- NVD entry for CVE-2020-36193 nvd.nist.gov/vuln/detail/CVE-2020-36193
- CISA Known Exploited Vulnerabilities catalog www.cisa.gov/known-exploited-vulnerabilities-catalog
- github.com github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916
- drupal.org www.drupal.org/sa-core-2021-001
- access.redhat.com access.redhat.com/security/cve/cve-2020-36193
- nvd.nist.gov nvd.nist.gov/vuln/detail/CVE-2020-36193