PatchSiren

Tubitak CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tubitak CVE published 2021-09-18

CVE-2021-3806

CVE-2021-3806 affects Pardus Software Center from TÜBİTAK/Pardus and is described by NVD as a path traversal issue in the extractArchive function. The issue can let an attacker influence file extraction and write files on the system, with the supplied summary noting a same-network man-in-the-middle scenario. NVD rates the issue CVSS 3.1 5.3 (Medium).