login
quiescence.eu
Zum Inhalt springen

CVE-2020-36193

PEAR Archive_Tar Improper Link Resolution Vulnerability

n/a
CVSS
70.6%
EPSS (exploit prob.)
99.3%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2022-08-25
Added

Summary

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

Affected software

Vendor: PEAR  ·  Product: Archive_Tar

Weakness types (CWE):

CWE-22CWE-59

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in PEAR

CVENameEPSSExploited
CVE-2020-28949 PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability 84.6% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.