First published: Wed Jan 08 2020(Updated: )
Fixed bug (Files added to tar with Phar::buildFromIterator have all-access permissions). (CVE-2020-7063)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-php73-php | <0:7.3.20-1.el7 | 0:7.3.20-1.el7 |
debian/php7.4 | 7.4.33-1+deb11u5 7.4.33-1+deb11u7 | |
PHP | <7.2.28 | 7.2.28 |
PHP | >=7.2.0<=7.2.27 | |
PHP | >=7.3.0<=7.3.14 | |
PHP | >=7.4.0<=7.4.2 | |
Tenable.sc | <5.19.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this bug is CVE-2020-7063.
The severity level of CVE-2020-7063 is medium.
PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15, and 7.4.x below 7.4.3 are affected by CVE-2020-7063.
To fix CVE-2020-7063, you should update your PHP version to 7.2.28, 7.3.15, or 7.4.3 or higher.
Yes, you can find more information about CVE-2020-7063 at the following references: [1](https://bugs.php.net/bug.php?id=79082), [2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1808537), [3](http://git.php.net/?p=php-src.git;a=commit;h=e5c95234d87fcb8f6b7569a96a89d1e1544749a6).