CVE-2020-36193highunder attackCWE-59

CVE-2020-36193

Published · Updated

73Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.5epss 71%
from disclosure to weapon
Published on NVDJan 18
CISA KEV+584d
exploitation probability
71%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (7 components)
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 6 · Red Hat Software Collections
no_fix_planned: Out of support scope
Fixed
4 products (606 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream EUS (v.8.4) · Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Workstation (v. 7)
Not affected
1 product — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9
Action required by CISAfederal deadline: 2022-09-15

Apply updates per vendor instructions.

In short

Archive_Tar library fails to properly validate symbolic links when extracting tar files, allowing attackers to write files outside the intended directory. This could let someone overwrite important system files or inject malicious code.

Technical detail

Archive_Tar versions ≤1.4.11 are vulnerable to directory traversal via inadequate symbolic link validation during tar extraction. An attacker with a crafted tar archive can exploit this to write files to arbitrary locations on the filesystem, bypassing intended extraction boundaries and potentially compromising system integrity.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
n/a · n/a