Directory Traversal in Archive_Tar
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
There was an initial fix for this vulnerability made in version 1.4.12. That fix introduced a bug which was fixed in 1.4.13. Therefore we have set the first-patched-version to 1.4.13 which the earliest working version that avoids this vulnerability.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 75.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 100.00 |
VPI 公式 vpi-v1
必要措施
Apply updates per vendor instructions.