CVE-2020-36193
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Archive_Tar library fails to properly validate symbolic links when extracting tar files, allowing attackers to write files outside the intended directory. This could let someone overwrite important system files or inject malicious code.
Archive_Tar versions ≤1.4.11 are vulnerable to directory traversal via inadequate symbolic link validation during tar extraction. An attacker with a crafted tar archive can exploit this to write files to arbitrary locations on the filesystem, bypassing intended extraction boundaries and potentially compromising system integrity.
The full analysis of this CVE is available in Portuguese →