{"id":"GHSA-f3xw-vgc7-f7h8","summary":"PEAR::Archive_Tar Directory Traversal vulnerability","details":"Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.","aliases":["CVE-2006-0931"],"modified":"2024-10-30T18:27:30.677082Z","published":"2022-05-01T06:43:51Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-10-30T18:09:28Z","nvd_published_at":"2006-02-28T11:02:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0931"},{"type":"PACKAGE","url":"https://github.com/pear/Archive_Tar"},{"type":"WEB","url":"http://pear.php.net/bugs/bug.php?id=6933"},{"type":"WEB","url":"http://pear.php.net/package/Archive_Tar/download"},{"type":"WEB","url":"http://www.hamid.ir/security/phptar.txt"}],"affected":[{"package":{"name":"pear/archive_tar","ecosystem":"Packagist","purl":"pkg:composer/pear/archive_tar"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2"},{"fixed":"1.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f3xw-vgc7-f7h8/GHSA-f3xw-vgc7-f7h8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}