Input validation error in Archive_Tar - CVE-2020-28949

 

Input validation error in Archive_Tar - CVE-2020-28949

Published: November 19, 2020 / Updated: October 3, 2022


Vulnerability identifier: #VU48668
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28949
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper sanitization of the user-supplied input when processing URI handlers in filenames. A remote attacker can pass the "file://" string in the filename and overwrite arbitrary files on the system.


Affected software

Archive_Tar
Oracle Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Backdrop CMS
Drupal
php-pear (Debian package)
drupal7 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
drupal7 (Ubuntu package)
libzip-tools
libzip-devel
libzip
php-pear
php-pear (Red Hat package)
php-pear (Ubuntu package)
php-pecl-zip
php-pecl-rrd
php-pecl-xdebug
php-pecl-apcu-devel
php-pecl-apcu
apcu-panel
php-xmlrpc
php-xml
php-soap
php-snmp
php-process
php-pgsql
php-mbstring
php-pdo
php-opcache
php-odbc
php-mysqlnd
php-json
php
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-devel
php-embedded
php-enchant
php-ffi
php-fpm
php-gd
php-gmp
php-intl
php-ldap
drupal7
drupal8

How to mitigate CVE-2020-28949

Install updates from vendor's website.

Archive_Tar - update to 1.4.11
Backdrop CMS - addressed in versions 1.16.6, 1.17.4
php-pear (Debian package) - update to 1.10.6+submodules+notgz-1.1+deb10u1
Drupal - addressed in versions 7.75, 8.8.12, 8.9.10, 9.0.9
drupal7 (Alpine package) - update to 7.75-r0
drupal7 (Ubuntu package) - update to Ubuntu Pro
libzip-tools - update to 1.6.1-1
libzip-devel - update to 1.6.1-1
libzip - update to 1.6.1-1
php-pear - addressed in versions 1.9.4-23, 1.10.13-1
php-pear (Red Hat package) - update to 1.9.4-23.el7_9
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz-6ubuntu0.2, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.2, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.1, 1:1.10.9+submodules+notgz-1ubuntu0.20.10.1
php-pear - addressed in versions 1.10.12-4.fc32, 1.10.12-4.fc33
php-pecl-zip - update to 1.18.2-1
php-pecl-rrd - update to 2.0.1-1
php-pecl-xdebug - update to 2.9.5-1
php-pecl-apcu-devel - update to 5.1.18-1
php-pecl-apcu - update to 5.1.18-1
apcu-panel - update to 5.1.18-1
php-xmlrpc - update to 7.4.19-4.0.1
php-xml - update to 7.4.19-4.0.1
php-soap - update to 7.4.19-4.0.1
php-snmp - update to 7.4.19-4.0.1
php-process - update to 7.4.19-4.0.1
php-pgsql - update to 7.4.19-4.0.1
php-mbstring - update to 7.4.19-4.0.1
php-pdo - update to 7.4.19-4.0.1
php-opcache - update to 7.4.19-4.0.1
php-odbc - update to 7.4.19-4.0.1
php-mysqlnd - update to 7.4.19-4.0.1
php-json - update to 7.4.19-4.0.1
php - update to 7.4.19-4.0.1
php-bcmath - update to 7.4.19-4.0.1
php-cli - update to 7.4.19-4.0.1
php-common - update to 7.4.19-4.0.1
php-dba - update to 7.4.19-4.0.1
php-dbg - update to 7.4.19-4.0.1
php-devel - update to 7.4.19-4.0.1
php-embedded - update to 7.4.19-4.0.1
php-enchant - update to 7.4.19-4.0.1
php-ffi - update to 7.4.19-4.0.1
php-fpm - update to 7.4.19-4.0.1
php-gd - update to 7.4.19-4.0.1
php-gmp - update to 7.4.19-4.0.1
php-intl - update to 7.4.19-4.0.1
php-ldap - update to 7.4.19-4.0.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35
drupal8 - addressed in versions 8.9.11-1.fc32, 8.9.11-1.fc33

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins