pear/archive_tar
Packagist6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pear/archive_tarpage 1 of 1
- CVE-2006-0931NONECVSS 0.0EG 0.0✓ Fixed in 1.3.22006-02-28
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.
- CVE-2018-1000888HIGHCVSS 8.8EG 8.8✓ Fixed in 1.4.42018-12-28
vulnerable: 1.3.11 ... 1.4.3 (10 versions)
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When ex…
- CVE-2020-28948HIGHCVSS 7.8EG 7.8✓ Fixed in 1.4.112020-11-19
vulnerable: 1.3.11 ... 1.4.9 (17 versions)
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
- CVE-2020-28949HIGHCVSS 7.8EG 9.0⚠ KEV✓ Fixed in 1.4.112020-11-19
vulnerable: 1.3.11 ... 1.4.9 (17 versions)
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
- CVE-2020-36193HIGHCVSS 7.5EG 9.0⚠ KEV✓ Fixed in 1.4.132021-01-18
vulnerable: 1.3.11 ... 1.4.9 (19 versions)
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
- CVE-2021-32610HIGHCVSS 7.1EG 7.1✓ Fixed in 1.4.142021-07-30
vulnerable: 1.3.11 ... 1.4.9 (20 versions)
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
Check whether pear/archive_tar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pear/archive_tar CVEs against the assets you own.
Start Free Scan →