CVE-2020-28949
19.11.2020, 19:15
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.Enginsight
| Vendor | Product | Version |
|---|---|---|
| php | archive_tar | 𝑥 < 1.4.12 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| drupal | drupal | 7.0 ≤ 𝑥 < 7.75 |
| drupal | drupal | 8.0.0 ≤ 𝑥 < 8.9.10 |
| drupal | drupal | 8.8.0 ≤ 𝑥 < 8.8.12 |
| drupal | drupal | 9.0.0 ≤ 𝑥 < 9.0.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| drupal7 |
| ||||||||||||||||||||||||
| php-pear |
|
References