Description
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2465-1 | php-pear security update |
Debian DLA |
DLA-2466-1 | drupal7 security update |
Debian DLA |
DLA-2621-1 | php-pear security update |
Debian DSA |
DSA-4817-1 | php-pear security update |
Github GHSA |
GHSA-jh5x-hfhg-78jq | Deserialization of Untrusted Data in Archive_Tar |
Ubuntu USN |
USN-4654-1 | PEAR vulnerabilities |
Ubuntu USN |
USN-6981-1 | Drupal vulnerabilities |
Ubuntu USN |
USN-6981-2 | Drupal vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:48:00.566Z
Reserved: 2020-11-19T00:00:00.000Z
Link: CVE-2020-28948
No data.
Status : Modified
Published: 2020-11-19T19:15:11.877
Modified: 2024-11-21T05:23:21.513
Link: CVE-2020-28948
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN