CVE-2020-28948: High severity archive::tar vulnerability
Published Nov 19, 2020
·Updated
ArchiveTar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Affected Software
14 affected componentsFixes available
redhat/php-pear<1:1.9.4-23.el7_9
1:1.9.4-23.el7_9
redhat/Archive_Tar<1.4.11
1.4.11
debian/php-pear
1:1.10.12+submodules+notgz+20210212-11:1.10.13+submodules+notgz+2022032202-2
PHP Archive Tar<1.4.11
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Drupal Drupal>=7.0<7.75
Drupal Drupal>=8.0.0<8.9.10
Drupal Drupal>=8.8.0<8.8.12
Drupal Drupal>=9.0.0<9.0.9
Remediation
Event History
Nov 19, 2020
CVE Published
12:00 AM
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
Aug 27, 2024
Data Sourced
via Launchpad·05:56 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·05:58 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-28948.
2
What is the severity of CVE-2020-28948?
The severity of CVE-2020-28948 is high, with a severity value of 7.8.
3
Which software is affected by CVE-2020-28948?
The software affected by CVE-2020-28948 includes Archive_Tar versions up to 1.4.10, php-pear versions up to 1:1.9.4-23.el7_9, and certain versions of Drupal, Debian, and Fedora.
4
How can I fix CVE-2020-28948?
To fix CVE-2020-28948, update to Archive_Tar version 1.4.11 or later, php-pear version 1:1.9.4-23.el7_9 or later, or the specified patched versions of Drupal, Debian, and Fedora.
5
Where can I find more information about CVE-2020-28948?
You can find more information about CVE-2020-28948 at the following references: [link1], [link2], [link3].