In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
{ "ubuntu_priority": "medium" }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.10.1+submodules+notgz-6ubuntu0.3+esm1", "binary_name": "php-pear" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.10.5+submodules+notgz-1ubuntu1.18.04.4", "binary_name": "php-pear" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.10.9+submodules+notgz-1ubuntu0.20.04.3", "binary_name": "php-pear" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:1.10.12+submodules+notgz+20210212-1ubuntu1", "binary_name": "php-pear" } ] }