CVE-2020-28949
19.11.2020, 19:15
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.Enginsight
Vendor | Product | Version |
---|---|---|
php | archive_tar | 𝑥 < 1.4.12 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
drupal | drupal | 7.0 ≤ 𝑥 < 7.75 |
drupal | drupal | 8.0.0 ≤ 𝑥 < 8.9.10 |
drupal | drupal | 8.8.0 ≤ 𝑥 < 8.8.12 |
drupal | drupal | 9.0.0 ≤ 𝑥 < 9.0.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
drupal7 |
| ||||||||||||||||||||||||
php-pear |
|
References