CVE-2021-32610
Summary
| CVE | CVE-2021-32610 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-30 14:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: drupal7-7.82-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: drupal7-7.82-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: php-pear-1.10.12-9.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Release 1.4.14 · pear/Archive_Tar · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: drupal7-7.82-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: drupal7-7.82-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: php-pear-1.10.12-9.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: php-pear-1.10.12-9.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: php-pear-1.10.12-9.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Drupal core - Critical - Drupal core - Critical - Third-party libraries - SA-CORE-2021-004 | Drupal.org |
CONFIRM |
www.drupal.org |
|
| Merge pull request #40 from mcdruid/master · pear/Archive_Tar@7789ebb · GitHub |
MISC |
github.com |
|
| Properly fix symbolic link path traversal (CVE-2021-32610) · pear/Archive_Tar@b583243 · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 2721-1] drupal7 security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160244 Oracle Enterprise Linux Security Update for php:7.4 (ELSA-2022-7628)
- 178726 Debian Security Update for drupal7 (DLA 2721-1)
- 182588 Debian Security Update for php-pear (CVE-2021-32610)
- 198447 Ubuntu Security Notification for PEAR vulnerability (USN-5027-1)
- 240855 Red Hat Update for php:7.4 security (RHSA-2022:7628)
- 281752 Fedora Security Update for php (FEDORA-2021-6cf271948a)
- 281753 Fedora Security Update for php (FEDORA-2021-c9c1f6e5c7)
- 281914 Fedora Security Update for drupal7 (FEDORA-2021-8093e197f4)
- 352835 Amazon Linux Security Advisory for php-pear: ALAS2-2021-1708
- 377999 Alibaba Cloud Linux Security Update for php:7.4 (ALINUX3-SA-2023:0018)
- 501838 Alpine Linux Security Update for drupal7
- 504706 Alpine Linux Security Update for drupal7
- 670722 EulerOS Security Update for php-pear (EulerOS-SA-2021-2480)
- 730163 Drupal Core Security Update (SA-CORE-2021-004)
- 753358 SUSE Enterprise Linux Security Update for php8-pear (SUSE-SU-2022:3198-1)
- 940756 AlmaLinux Security Update for php:7.4 (ALSA-2022:7628)
- 960333 Rocky Linux Security Update for php:7.4 (RLSA-2022:7628)