Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
},
{
"introduced": "0"
},
{
"last_affected": "10.0"
},
{
"introduced": "7.0"
},
{
"fixed": "7.78"
},
{
"introduced": "8.9.0"
},
{
"fixed": "8.9.13"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.0.11"
},
{
"introduced": "9.1.0"
},
{
"fixed": "9.1.3"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36193.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "35"
}
]
}
]