PT-2026-43162 · Bingos · Archive Tar
Published
2026-05-26
·
Updated
2026-05-26
·
CVE-2026-42496
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
make special file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.
A subsequent open through the extracted name reads or writes the attacker chosen path.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archive Tar