An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc1YzUtZjRndy0zOHI5

High EPSS: 0.93364% (0.998 Percentile) EPSS:

Multiple vulnerabilities through filename manipulation in Archive_Tar

Affected Packages Affected Versions Fixed Versions
packagist:pear/archive_tar < 1.4.11 1.4.11
70 Dependent packages
4,758 Dependent repositories
56,220,721 Downloads total

Affected Version Ranges

All affected versions

1.3.11, 1.3.12, 1.3.13, 1.3.14, 1.3.15, 1.3.16, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.4.10

All unaffected versions

1.4.11, 1.4.12, 1.4.13, 1.4.14, 1.5.0, 1.6.0

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. See: https://github.com/pear/Archive_Tar/issues/33

References: