Link following in Archive_Tar - CVE-2021-32610
Published: July 20, 2021 / Updated: July 22, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the application does not check if the file in the archive is a symbolic link when extracting it. A remote attacker can pass a specially crafted file to the application and overwrite arbitrary files on the system. Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Affected software
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Backdrop CMS
Drupal
IBM API Connect
Nextcloud Server
php-pear (Ubuntu package)
php-pear
php8-pecl
php8-pear
drupal7
How to mitigate CVE-2021-32610
Backdrop CMS - addressed in versions 1.18.6, 1.19.2
IBM API Connect - addressed in versions 10.0.1.4, 2018.4.1.17
Drupal - addressed in versions 7.82, 8.9.17, 9.1.11, 9.2.2
Nextcloud Server - addressed in versions 20.0.13, 21.0.5, 22.2.0
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz6ubuntu0.3+esm1, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.4, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.3, 1:1.10.9+submodules+notgz-1.1ubuntu1.1
php-pear - addressed in versions 1.10.12-9.fc33, 1.10.12-9.fc34
php8-pecl - update to 1.10.21-150400.9.3.1
php8-pear - update to 1.10.21-150400.9.3.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35
External References
Related Security Bulletins
- Symbolic link following in Archive_Tar
- Remote code execution in Backdrop Archive_Tar pear library
- Link following in Nextcloud Server
- Drupal update for Archive_Tar library
- Ubuntu update for php-pear
- Ubuntu update for php-pear
- Remote code execution in IBM API Connect
- SUSE update for php8-pear
- Red Hat Enterprise Linux 8 update for the php:7.4 module
- Multiple vulnerabilities in Oracle Linux
- Fedora 33 update for php-pear
- Fedora 34 update for php-pear
- Fedora EPEL 7 update for drupal7
- Fedora 34 update for drupal7
- Fedora 35 update for drupal7