Deserialization of Untrusted Data in Archive_Tar - CVE-2020-28948
Published: November 19, 2020 / Updated: October 3, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data, related to case sensitivity issues (e.g. "phar:" protocol is blocked, however "PHAR:" is not). A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle Linux
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Backdrop CMS
Drupal
php-pear (Debian package)
drupal7 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
drupal7 (Ubuntu package)
libzip-tools
libzip-devel
libzip
php-pear
php-pear (Red Hat package)
php-pear (Ubuntu package)
php-pecl-zip
php-pecl-rrd
php-pecl-xdebug
php-pecl-apcu-devel
php-pecl-apcu
apcu-panel
php-xmlrpc
php-xml
php-soap
php-snmp
php-process
php-pgsql
php-mbstring
php-pdo
php-opcache
php-odbc
php-mysqlnd
php-json
php
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-devel
php-embedded
php-enchant
php-ffi
php-fpm
php-gd
php-gmp
php-intl
php-ldap
drupal7
drupal8
How to mitigate CVE-2020-28948
Backdrop CMS - addressed in versions 1.16.6, 1.17.4
php-pear (Debian package) - update to 1.10.6+submodules+notgz-1.1+deb10u1
Drupal - addressed in versions 7.75, 8.8.12, 8.9.10, 9.0.9
drupal7 (Alpine package) - update to 7.75-r0
drupal7 (Ubuntu package) - update to Ubuntu Pro
libzip-tools - update to 1.6.1-1
libzip-devel - update to 1.6.1-1
libzip - update to 1.6.1-1
php-pear - addressed in versions 1.9.4-23, 1.10.13-1
php-pear (Red Hat package) - update to 1.9.4-23.el7_9
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz-6ubuntu0.2, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.2, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.1, 1:1.10.9+submodules+notgz-1ubuntu0.20.10.1
php-pear - addressed in versions 1.10.12-4.fc32, 1.10.12-4.fc33
php-pecl-zip - update to 1.18.2-1
php-pecl-rrd - update to 2.0.1-1
php-pecl-xdebug - update to 2.9.5-1
php-pecl-apcu-devel - update to 5.1.18-1
php-pecl-apcu - update to 5.1.18-1
apcu-panel - update to 5.1.18-1
php-xmlrpc - update to 7.4.19-4.0.1
php-xml - update to 7.4.19-4.0.1
php-soap - update to 7.4.19-4.0.1
php-snmp - update to 7.4.19-4.0.1
php-process - update to 7.4.19-4.0.1
php-pgsql - update to 7.4.19-4.0.1
php-mbstring - update to 7.4.19-4.0.1
php-pdo - update to 7.4.19-4.0.1
php-opcache - update to 7.4.19-4.0.1
php-odbc - update to 7.4.19-4.0.1
php-mysqlnd - update to 7.4.19-4.0.1
php-json - update to 7.4.19-4.0.1
php - update to 7.4.19-4.0.1
php-bcmath - update to 7.4.19-4.0.1
php-cli - update to 7.4.19-4.0.1
php-common - update to 7.4.19-4.0.1
php-dba - update to 7.4.19-4.0.1
php-dbg - update to 7.4.19-4.0.1
php-devel - update to 7.4.19-4.0.1
php-embedded - update to 7.4.19-4.0.1
php-enchant - update to 7.4.19-4.0.1
php-ffi - update to 7.4.19-4.0.1
php-fpm - update to 7.4.19-4.0.1
php-gd - update to 7.4.19-4.0.1
php-gmp - update to 7.4.19-4.0.1
php-intl - update to 7.4.19-4.0.1
php-ldap - update to 7.4.19-4.0.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35
drupal8 - addressed in versions 8.9.11-1.fc32, 8.9.11-1.fc33
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in PEAR Archive_Tar library
- Remote code execution in Drupal
- Remote code execution in Backdrop core
- Deserialization of Untrusted Data in drupal7 (Alpine package)
- Debian update for php-pear
- Amazon Linux AMI update for php7-pear
- Gentoo update for PEAR Archive_Tar
- Arch Linux update for nextcloud
- Red Hat Enterprise Linux 8 update for the php:7.4 module
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the php:7.4 module
- Red Hat Enterprise Linux 7 update for php-pear
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for drupal7
- Ubuntu update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora 34 update for drupal7
- Fedora 35 update for drupal7
- Anolis OS update for php:7.4 module
- Anolis OS update for php-pear
- Ubuntu update for php-pear
- Fedora 33 update for php-pear
- Fedora 32 update for php-pear
- Fedora 32 update for drupal8
- Fedora 33 update for drupal8