In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:1.10.5+submodules+notgz-1ubuntu1.18.04.4", "binary_name": "php-pear" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-32610.json"
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:1.10.9+submodules+notgz-1ubuntu0.20.04.3", "binary_name": "php-pear" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:1.10.12+submodules+notgz+20210212-1ubuntu1", "binary_name": "php-pear" } ] }
{ "binaries": [ { "binary_version": "7.26-1ubuntu0.1+esm3", "binary_name": "drupal7" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "1:1.10.1+submodules+notgz-6ubuntu0.3+esm1", "binary_name": "php-pear" } ] }
{ "binaries": [ { "binary_version": "7.44-1ubuntu1~16.04.0+esm3", "binary_name": "drupal7" } ] }