Link following in Archive_Tar - CVE-2021-32610

 

Link following in Archive_Tar - CVE-2021-32610

Published: July 20, 2021 / Updated: July 22, 2021


Vulnerability identifier: #VU55101
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32610
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to the application does not check if the file in the archive is a symbolic link when extracting it. A remote attacker can pass a specially crafted file to the application and overwrite arbitrary files on the system. Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Archive_Tar
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Backdrop CMS
Drupal
IBM API Connect
Nextcloud Server
php-pear (Ubuntu package)
php-pear
php8-pecl
php8-pear
drupal7

How to mitigate CVE-2021-32610

Install updates from vendor's website.

Archive_Tar - update to 1.4.14
Backdrop CMS - addressed in versions 1.18.6, 1.19.2
IBM API Connect - addressed in versions 10.0.1.4, 2018.4.1.17
Drupal - addressed in versions 7.82, 8.9.17, 9.1.11, 9.2.2
Nextcloud Server - addressed in versions 20.0.13, 21.0.5, 22.2.0
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz6ubuntu0.3+esm1, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.4, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.3, 1:1.10.9+submodules+notgz-1.1ubuntu1.1
php-pear - addressed in versions 1.10.12-9.fc33, 1.10.12-9.fc34
php8-pecl - update to 1.10.21-150400.9.3.1
php8-pear - update to 1.10.21-150400.9.3.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35

External References

Related Security Bulletins