CVE-2020-28949
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 85% (אחוזון 100) נכון ל-30/7/2026
מוצרים מושפעים
php: archive tar; debian: debian linux; fedoraproject: fedora; drupal: drupal
קישורים
- https://github.com/pear/Archive_Tar/issues/33 ExploitIssue TrackingVendor Advisory
- https://github.com/pear/Archive_Tar/issues/33 ExploitIssue TrackingVendor Advisory
- http://packetstormsecurity.com/files/161095/PEAR-Archive_Tar-Arbitrary-File-Wr… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161095/PEAR-Archive_Tar-Arbitrary-File-Wr… ExploitThird Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2020/11/msg00045.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListThird Party Advisory