Multiple vulnerabilities through filename manipulation in Archive_Tar
Affected range
ECOSYSTEM: introduced 0; fixed 1.4.11<1.4.11Fixed versions: 1.4.11
Tar file management class with compression support (gzip, bzip2, lzma2)
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
1.6.1
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Critical
5 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 0; fixed 1.4.11<1.4.11Fixed versions: 1.4.11
Affected range
ECOSYSTEM: introduced 0; fixed 1.4.13<1.4.12Fixed versions: 1.4.13
Affected range
ECOSYSTEM: introduced 1.2; fixed 1.3.2>=1.2,<1.3.2Fixed versions: 1.3.2
Affected range
ECOSYSTEM: introduced 0; fixed 1.4.14<1.4.14Fixed versions: 1.4.14
Affected range
ECOSYSTEM: introduced 0; fixed 1.4.4<1.4.4Fixed versions: 1.4.4