#VU55101 Link following in Archive_Tar - CVE-2021-32610
Published: July 20, 2021 / Updated: July 22, 2021
Archive_Tar
PHP Group
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the application does not check if the file in the archive is a symbolic link when extracting it. A remote attacker can pass a specially crafted file to the application and overwrite arbitrary files on the system. Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.