Skip to content
COOEY

FAIL › dossier

Archive_Tar

PRODUCT

· dossier confidence 20%

Archive_Tar, a PEAR package, has been linked to multiple security issues, including remote code execution and denial of service vulnerabilities.

PROFILE
CategorysoftwareWhat they doArchive_Tar is a PEAR package used for handling Tar archives, which is a type of archive file format. Websitehttps://pear.php.net/package/Archive_Tar ↗
SECURITY POSTURE

The product has been associated with multiple security vulnerabilities, including remote code execution and denial of service.

Notable failures
  • CVE-2020-28949: High [RCE] - Untrusted unserialization allowed remote code execution.
  • CVE-2020-36193: High [RCE] - Exposed directory traversal due to poor symbolic link checking, leading to potential unauthorized access.
Patterns: Repeated untrusted unserialization vulnerabilities.; Poorly implemented security checks leading to code execution vulnerabilities.
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-08-25 CVE-2020-28949 high PEAR Archive_Tar untrusted unserialization allowed remote code execution
2022-08-25 CVE-2020-36193 high PEAR's Archive_Tar module exposed directory traversal due to poor symbolic link checking, leading to potential unauthorized access.
Open questions: How has the company addressed these vulnerabilities? · What is the company's overall security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:42:14.938885+00:00