Deserialization of Untrusted Data in Archive_Tar - CVE-2020-28948

 

Deserialization of Untrusted Data in Archive_Tar - CVE-2020-28948

Published: November 19, 2020 / Updated: October 3, 2022


Vulnerability identifier: #VU48669
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28948
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data, related to case sensitivity issues (e.g. "phar:" protocol is blocked, however  "PHAR:" is not). A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Archive_Tar
Oracle Linux
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Backdrop CMS
Drupal
php-pear (Debian package)
drupal7 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
drupal7 (Ubuntu package)
libzip-tools
libzip-devel
libzip
php-pear
php-pear (Red Hat package)
php-pear (Ubuntu package)
php-pecl-zip
php-pecl-rrd
php-pecl-xdebug
php-pecl-apcu-devel
php-pecl-apcu
apcu-panel
php-xmlrpc
php-xml
php-soap
php-snmp
php-process
php-pgsql
php-mbstring
php-pdo
php-opcache
php-odbc
php-mysqlnd
php-json
php
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-devel
php-embedded
php-enchant
php-ffi
php-fpm
php-gd
php-gmp
php-intl
php-ldap
drupal7
drupal8

How to mitigate CVE-2020-28948

Install updates from vendor's website.

Archive_Tar - update to 1.4.11
Backdrop CMS - addressed in versions 1.16.6, 1.17.4
php-pear (Debian package) - update to 1.10.6+submodules+notgz-1.1+deb10u1
Drupal - addressed in versions 7.75, 8.8.12, 8.9.10, 9.0.9
drupal7 (Alpine package) - update to 7.75-r0
drupal7 (Ubuntu package) - update to Ubuntu Pro
libzip-tools - update to 1.6.1-1
libzip-devel - update to 1.6.1-1
libzip - update to 1.6.1-1
php-pear - addressed in versions 1.9.4-23, 1.10.13-1
php-pear (Red Hat package) - update to 1.9.4-23.el7_9
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz-6ubuntu0.2, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.2, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.1, 1:1.10.9+submodules+notgz-1ubuntu0.20.10.1
php-pear - addressed in versions 1.10.12-4.fc32, 1.10.12-4.fc33
php-pecl-zip - update to 1.18.2-1
php-pecl-rrd - update to 2.0.1-1
php-pecl-xdebug - update to 2.9.5-1
php-pecl-apcu-devel - update to 5.1.18-1
php-pecl-apcu - update to 5.1.18-1
apcu-panel - update to 5.1.18-1
php-xmlrpc - update to 7.4.19-4.0.1
php-xml - update to 7.4.19-4.0.1
php-soap - update to 7.4.19-4.0.1
php-snmp - update to 7.4.19-4.0.1
php-process - update to 7.4.19-4.0.1
php-pgsql - update to 7.4.19-4.0.1
php-mbstring - update to 7.4.19-4.0.1
php-pdo - update to 7.4.19-4.0.1
php-opcache - update to 7.4.19-4.0.1
php-odbc - update to 7.4.19-4.0.1
php-mysqlnd - update to 7.4.19-4.0.1
php-json - update to 7.4.19-4.0.1
php - update to 7.4.19-4.0.1
php-bcmath - update to 7.4.19-4.0.1
php-cli - update to 7.4.19-4.0.1
php-common - update to 7.4.19-4.0.1
php-dba - update to 7.4.19-4.0.1
php-dbg - update to 7.4.19-4.0.1
php-devel - update to 7.4.19-4.0.1
php-embedded - update to 7.4.19-4.0.1
php-enchant - update to 7.4.19-4.0.1
php-ffi - update to 7.4.19-4.0.1
php-fpm - update to 7.4.19-4.0.1
php-gd - update to 7.4.19-4.0.1
php-gmp - update to 7.4.19-4.0.1
php-intl - update to 7.4.19-4.0.1
php-ldap - update to 7.4.19-4.0.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35
drupal8 - addressed in versions 8.9.11-1.fc32, 8.9.11-1.fc33

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins