FAIL › dossier
Archive_Tar
PRODUCT· dossier confidence 20%
Archive_Tar, a PEAR package, has been linked to multiple security issues, including remote code execution and denial of service vulnerabilities.
PROFILE
CategorysoftwareWhat they doArchive_Tar is a PEAR package used for handling Tar archives, which is a type of archive file format.
Websitehttps://pear.php.net/package/Archive_Tar ↗
SECURITY POSTURE
The product has been associated with multiple security vulnerabilities, including remote code execution and denial of service.
Notable failures
- CVE-2020-28949: High [RCE] - Untrusted unserialization allowed remote code execution.
- CVE-2020-36193: High [RCE] - Exposed directory traversal due to poor symbolic link checking, leading to potential unauthorized access.
Patterns: Repeated untrusted unserialization vulnerabilities.; Poorly implemented security checks leading to code execution vulnerabilities.
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-08-25 | CVE-2020-28949 | high | PEAR Archive_Tar untrusted unserialization allowed remote code execution |
| 2022-08-25 | CVE-2020-36193 | high | PEAR's Archive_Tar module exposed directory traversal due to poor symbolic link checking, leading to potential unauthorized access. |
DOSSIER SOURCES
- RHSA-2026:49523 - Security Advisory - Red Hat Customer Portal · access.redhat.com
- RHSA-2026:49524 - Security Advisory - Red Hat カスタマーポータル · access.redhat.com
- Rocky Linux perl-Archive-Tar Important Denial of Service 2026-49525 · linuxsecurity.com
Open questions: How has the company addressed these vulnerabilities? · What is the company's overall security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:42:14.938885+00:00