CVE-2020-28948
Summary
| CVE | CVE-2020-28948 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 19:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: php-pear-1.10.12-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 35 Update: drupal7-7.82-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: drupal8-8.9.11-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: drupal8-8.9.11-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2466-1] drupal7 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 34 Update: drupal7-7.82-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Multiple vulnerabilities through filename manipulation · Issue #33 · pear/Archive_Tar · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 33 Update: php-pear-1.10.12-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: drupal8-8.9.11-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 35 Update: drupal7-7.82-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: drupal7-7.82-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: php-pear-1.10.12-4.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-4817-1 php-pear |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: php-pear-1.10.12-4.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| PEAR Archive_Tar: Directory traversal (GLSA 202101-23) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: drupal8-8.9.11-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-013 | Drupal.org |
CONFIRM |
www.drupal.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154101 Drupal Core Arbitrary Code Execution Vulnerability (SA-CORE-2020-013)
- 160100 Oracle Enterprise Linux Security Update for php:7.4 (ELSA-2022-6542)
- 160197 Oracle Enterprise Linux Security Update for php-pear (ELSA-2022-7340)
- 178538 Debian Security Update for php-pear (DLA 2621-1)
- 240672 Red Hat Update for php:7.4 (RHSA-2022:6542)
- 240674 Red Hat Update for php:7.4 (RHSA-2022:6541)
- 240810 Red Hat Update for php-pear (RHSA-2022:7340)
- 281914 Fedora Security Update for drupal7 (FEDORA-2021-8093e197f4)
- 377605 Alibaba Cloud Linux Security Update for php:7.4 (ALINUX3-SA-2022:0161)
- 377760 Alibaba Cloud Linux Security Update for php-pear (ALINUX2-SA-2022:0052)
- 500879 Alpine Linux Security Update for drupal7
- 504703 Alpine Linux Security Update for drupal7
- 670340 EulerOS Security Update for php-pear (EulerOS-SA-2021-1884)
- 940671 AlmaLinux Security Update for php:7.4 (ALSA-2022:6542)
- 960355 Rocky Linux Security Update for php:7.4 (RLSA-2022:6542)