Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
| Vendor | Product | Versions |
|---|---|---|
| archive\ | \ | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| cpanel | cpanel/whm | cert_advisory | 90% |
Updated severity to CRITICAL, changed exploit availability to false, and provided a more detailed description of the vulnerability.
Updated description, vendor to CPAN Security Group, product to Archive-Tar, affected versions to 'before 3.08', severity to HIGH, CVSS estimate to 7.8, added CWE-59, set exploitAvailable to true, added MITRE ATT&CK technique T1505.003, and added tags 'symlink' and 'path traversal'.
Initial creation