Executive brief
PEAR Archive_Tar through 1.4.11 is vulnerable to directory traversal during write operations. The flaw exists in Tar.php due to inadequate validation of symbolic links, allowing an attacker to write files to arbitrary locations outside the intended directory.
Affected products
- PEAR Archive_Tar through 1.4.11
- Drupal Core
- Red Hat Enterprise Linux
Timeline
- 2021-01-18: patched: Patch committed to GitHub repository.
- 2022-08-25: disclosed: Vulnerability published.
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2022-08-25: exploited: Reported as exploited in the wild.