CVE record
CVE-2020-36193
PEAR Archive_Tar Improper Link Resolution Vulnerability
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
high
CVSS 7.5 ยท CVSS_V3
Affected packages
1
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- PEAR
- Product
- Archive_Tar
- Date added
- Aug 25, 2022
- CISA federal remediation due date
- Sep 15, 2022
- Required action
- Apply updates per vendor instructions.
- Known ransomware campaign use
- Unknown
- CWE
- CWE-22, CWE-59
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| pear/archive_tar | composer | 1.4.13 |