UNIX symbolic link following in Archive_Tar - CVE-2020-36193
Published: January 18, 2021 / Updated: October 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a symlink following issue in tar.php file in Archive_Tar. A remote attacker can pass specially crafted archive to the application and force the application to overwrite arbitrary files on the system using directory traversal sequences.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Affected software
Gentoo Linux
Oracle Linux
Arch Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Software Development Kit
Ubuntu
Backdrop CMS
Drupal
php-pear (Debian package)
drupal7 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libzip-tools
libzip-devel
libzip
php-pear
php-pear (Red Hat package)
php-pear (Ubuntu package)
php74-pecl
php74-pear
php7-pecl
php7-pear
php-pecl-zip
php-pecl-rrd
php-pecl-xdebug
php-pecl-apcu
php-pecl-apcu-devel
apcu-panel
php72-snmp
php72-sysvsem
php72-snmp-debuginfo
php72-soap-debuginfo
php72-sockets
php72-sockets-debuginfo
php72-sodium
php72-sodium-debuginfo
php72-sqlite
php72-sqlite-debuginfo
php72-sysvmsg
php72-sysvmsg-debuginfo
php72-shmop-debuginfo
php72-shmop
php72-readline-debuginfo
php72-readline
php72-pspell-debuginfo
php72-pspell
php72-posix-debuginfo
php72-posix
php72-phar-debuginfo
php72-phar
php72-soap
php72-pgsql-debuginfo
php72-xmlrpc
php72-pear-Archive_Tar
php72-pear
php72-zlib-debuginfo
php72-zlib
php72-zip-debuginfo
php72-zip
php72-xsl-debuginfo
php72-xsl
php72-xmlwriter-debuginfo
php72-xmlwriter
php72-xmlrpc-debuginfo
php72-sysvsem-debuginfo
php72-xmlreader-debuginfo
php72-xmlreader
php72-wddx-debuginfo
php72-wddx
php72-tokenizer-debuginfo
php72-tokenizer
php72-tidy-debuginfo
php72-tidy
php72-sysvshm-debuginfo
php72-sysvshm
php72-curl-debuginfo
php72-ftp
php72-fpm-debuginfo
php72-fpm
php72-fileinfo-debuginfo
php72-fileinfo
php72-fastcgi-debuginfo
php72-fastcgi
php72-exif-debuginfo
php72-exif
php72-enchant-debuginfo
php72-enchant
php72-dom-debuginfo
php72-dom
php72-dba-debuginfo
php72-dba
php72-pdo-debuginfo
php72-curl
php72-ctype-debuginfo
php72-ctype
php72-calendar-debuginfo
php72-calendar
php72-bz2-debuginfo
php72-bz2
php72-bcmath-debuginfo
php72-bcmath
php72
apache2-mod_php72-debuginfo
apache2-mod_php72
php72-devel
php72-debugsource
php72-debuginfo
php72-gd
php72-pgsql
php72-pdo
php72-pcntl-debuginfo
php72-pcntl
php72-openssl-debuginfo
php72-openssl
php72-opcache-debuginfo
php72-opcache
php72-odbc-debuginfo
php72-odbc
php72-mysql-debuginfo
php72-mysql
php72-mbstring-debuginfo
php72-mbstring
php72-ldap-debuginfo
php72-json-debuginfo
php72-ldap
php72-ftp-debuginfo
php72-gd-debuginfo
php72-gettext
php72-gettext-debuginfo
php72-gmp
php72-gmp-debuginfo
php72-iconv
php72-imap
php72-iconv-debuginfo
php72-imap-debuginfo
php72-intl
php72-intl-debuginfo
php72-json
php-gmp
php-intl
php-json
php-ldap
php-embedded
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-xmlrpc
php-snmp
php-soap
php-xml
php-fpm
php-ffi
php-enchant
php-devel
php-dbg
php-dba
php-common
php-cli
php
php-gd
php-bcmath
drupal7
How to mitigate CVE-2020-36193
Backdrop CMS - addressed in versions 1.17.6, 1.18.1
php-pear (Debian package) - update to 1:1.10.6+submodules+notgz-1.1+deb10u2
Drupal - addressed in versions 7.78, 8.9.13, 9.0.11, 9.1.3
drupal7 (Alpine package) - update to 7.78-r0
libzip-tools - update to 1.6.1-1
libzip-devel - update to 1.6.1-1
libzip - update to 1.6.1-1
php-pear - addressed in versions 1.9.4-23, 1.10.13-1
php-pear (Red Hat package) - update to 1.9.4-23.el7_9
php-pear (Ubuntu package) - addressed in versions 1:1.10.1+submodules+notgz-6ubuntu0.3, 1:1.10.5+submodules+notgz-1ubuntu1.18.04.3, 1:1.10.9+submodules+notgz-1ubuntu0.20.04.2, 1:1.10.9+submodules+notgz-1ubuntu0.20.10.2
php-pear - addressed in versions 1.10.12-5.fc32, 1.10.12-5.fc33
php74-pecl - update to 1.10.21-1.6.1
php74-pear - update to 1.10.21-1.6.1
php7-pecl - update to 1.10.21-3.6.1
php7-pear - update to 1.10.21-3.6.1
php-pecl-zip - update to 1.18.2-1
php-pecl-rrd - update to 2.0.1-1
php-pecl-xdebug - update to 2.9.5-1
php-pecl-apcu - update to 5.1.18-1
php-pecl-apcu-devel - update to 5.1.18-1
apcu-panel - update to 5.1.18-1
php72-snmp - update to 7.2.5-1.69.1
php72-sysvsem - update to 7.2.5-1.69.1
php72-snmp-debuginfo - update to 7.2.5-1.69.1
php72-soap-debuginfo - update to 7.2.5-1.69.1
php72-sockets - update to 7.2.5-1.69.1
php72-sockets-debuginfo - update to 7.2.5-1.69.1
php72-sodium - update to 7.2.5-1.69.1
php72-sodium-debuginfo - update to 7.2.5-1.69.1
php72-sqlite - update to 7.2.5-1.69.1
php72-sqlite-debuginfo - update to 7.2.5-1.69.1
php72-sysvmsg - update to 7.2.5-1.69.1
php72-sysvmsg-debuginfo - update to 7.2.5-1.69.1
php72-shmop-debuginfo - update to 7.2.5-1.69.1
php72-shmop - update to 7.2.5-1.69.1
php72-readline-debuginfo - update to 7.2.5-1.69.1
php72-readline - update to 7.2.5-1.69.1
php72-pspell-debuginfo - update to 7.2.5-1.69.1
php72-pspell - update to 7.2.5-1.69.1
php72-posix-debuginfo - update to 7.2.5-1.69.1
php72-posix - update to 7.2.5-1.69.1
php72-phar-debuginfo - update to 7.2.5-1.69.1
php72-phar - update to 7.2.5-1.69.1
php72-soap - update to 7.2.5-1.69.1
php72-pgsql-debuginfo - update to 7.2.5-1.69.1
php72-xmlrpc - update to 7.2.5-1.69.1
php72-pear-Archive_Tar - update to 7.2.5-1.69.1
php72-pear - update to 7.2.5-1.69.1
php72-zlib-debuginfo - update to 7.2.5-1.69.1
php72-zlib - update to 7.2.5-1.69.1
php72-zip-debuginfo - update to 7.2.5-1.69.1
php72-zip - update to 7.2.5-1.69.1
php72-xsl-debuginfo - update to 7.2.5-1.69.1
php72-xsl - update to 7.2.5-1.69.1
php72-xmlwriter-debuginfo - update to 7.2.5-1.69.1
php72-xmlwriter - update to 7.2.5-1.69.1
php72-xmlrpc-debuginfo - update to 7.2.5-1.69.1
php72-sysvsem-debuginfo - update to 7.2.5-1.69.1
php72-xmlreader-debuginfo - update to 7.2.5-1.69.1
php72-xmlreader - update to 7.2.5-1.69.1
php72-wddx-debuginfo - update to 7.2.5-1.69.1
php72-wddx - update to 7.2.5-1.69.1
php72-tokenizer-debuginfo - update to 7.2.5-1.69.1
php72-tokenizer - update to 7.2.5-1.69.1
php72-tidy-debuginfo - update to 7.2.5-1.69.1
php72-tidy - update to 7.2.5-1.69.1
php72-sysvshm-debuginfo - update to 7.2.5-1.69.1
php72-sysvshm - update to 7.2.5-1.69.1
php72-curl-debuginfo - update to 7.2.5-1.69.1
php72-ftp - update to 7.2.5-1.69.1
php72-fpm-debuginfo - update to 7.2.5-1.69.1
php72-fpm - update to 7.2.5-1.69.1
php72-fileinfo-debuginfo - update to 7.2.5-1.69.1
php72-fileinfo - update to 7.2.5-1.69.1
php72-fastcgi-debuginfo - update to 7.2.5-1.69.1
php72-fastcgi - update to 7.2.5-1.69.1
php72-exif-debuginfo - update to 7.2.5-1.69.1
php72-exif - update to 7.2.5-1.69.1
php72-enchant-debuginfo - update to 7.2.5-1.69.1
php72-enchant - update to 7.2.5-1.69.1
php72-dom-debuginfo - update to 7.2.5-1.69.1
php72-dom - update to 7.2.5-1.69.1
php72-dba-debuginfo - update to 7.2.5-1.69.1
php72-dba - update to 7.2.5-1.69.1
php72-pdo-debuginfo - update to 7.2.5-1.69.1
php72-curl - update to 7.2.5-1.69.1
php72-ctype-debuginfo - update to 7.2.5-1.69.1
php72-ctype - update to 7.2.5-1.69.1
php72-calendar-debuginfo - update to 7.2.5-1.69.1
php72-calendar - update to 7.2.5-1.69.1
php72-bz2-debuginfo - update to 7.2.5-1.69.1
php72-bz2 - update to 7.2.5-1.69.1
php72-bcmath-debuginfo - update to 7.2.5-1.69.1
php72-bcmath - update to 7.2.5-1.69.1
php72 - update to 7.2.5-1.69.1
apache2-mod_php72-debuginfo - update to 7.2.5-1.69.1
apache2-mod_php72 - update to 7.2.5-1.69.1
php72-devel - update to 7.2.5-1.69.1
php72-debugsource - update to 7.2.5-1.69.1
php72-debuginfo - update to 7.2.5-1.69.1
php72-gd - update to 7.2.5-1.69.1
php72-pgsql - update to 7.2.5-1.69.1
php72-pdo - update to 7.2.5-1.69.1
php72-pcntl-debuginfo - update to 7.2.5-1.69.1
php72-pcntl - update to 7.2.5-1.69.1
php72-openssl-debuginfo - update to 7.2.5-1.69.1
php72-openssl - update to 7.2.5-1.69.1
php72-opcache-debuginfo - update to 7.2.5-1.69.1
php72-opcache - update to 7.2.5-1.69.1
php72-odbc-debuginfo - update to 7.2.5-1.69.1
php72-odbc - update to 7.2.5-1.69.1
php72-mysql-debuginfo - update to 7.2.5-1.69.1
php72-mysql - update to 7.2.5-1.69.1
php72-mbstring-debuginfo - update to 7.2.5-1.69.1
php72-mbstring - update to 7.2.5-1.69.1
php72-ldap-debuginfo - update to 7.2.5-1.69.1
php72-json-debuginfo - update to 7.2.5-1.69.1
php72-ldap - update to 7.2.5-1.69.1
php72-ftp-debuginfo - update to 7.2.5-1.69.1
php72-gd-debuginfo - update to 7.2.5-1.69.1
php72-gettext - update to 7.2.5-1.69.1
php72-gettext-debuginfo - update to 7.2.5-1.69.1
php72-gmp - update to 7.2.5-1.69.1
php72-gmp-debuginfo - update to 7.2.5-1.69.1
php72-iconv - update to 7.2.5-1.69.1
php72-imap - update to 7.2.5-1.69.1
php72-iconv-debuginfo - update to 7.2.5-1.69.1
php72-imap-debuginfo - update to 7.2.5-1.69.1
php72-intl - update to 7.2.5-1.69.1
php72-intl-debuginfo - update to 7.2.5-1.69.1
php72-json - update to 7.2.5-1.69.1
php-gmp - update to 7.4.19-4.0.1
php-intl - update to 7.4.19-4.0.1
php-json - update to 7.4.19-4.0.1
php-ldap - update to 7.4.19-4.0.1
php-embedded - update to 7.4.19-4.0.1
php-mbstring - update to 7.4.19-4.0.1
php-mysqlnd - update to 7.4.19-4.0.1
php-odbc - update to 7.4.19-4.0.1
php-opcache - update to 7.4.19-4.0.1
php-pdo - update to 7.4.19-4.0.1
php-pgsql - update to 7.4.19-4.0.1
php-process - update to 7.4.19-4.0.1
php-xmlrpc - update to 7.4.19-4.0.1
php-snmp - update to 7.4.19-4.0.1
php-soap - update to 7.4.19-4.0.1
php-xml - update to 7.4.19-4.0.1
php-fpm - update to 7.4.19-4.0.1
php-ffi - update to 7.4.19-4.0.1
php-enchant - update to 7.4.19-4.0.1
php-devel - update to 7.4.19-4.0.1
php-dbg - update to 7.4.19-4.0.1
php-dba - update to 7.4.19-4.0.1
php-common - update to 7.4.19-4.0.1
php-cli - update to 7.4.19-4.0.1
php - update to 7.4.19-4.0.1
php-gd - update to 7.4.19-4.0.1
php-bcmath - update to 7.4.19-4.0.1
drupal7 - addressed in versions 7.82-1.el7, 7.82-1.fc34, 7.82-1.fc35
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Archive_Tar
- Remote code execution in pear Archive_Tar library in Drupal
- Remote code execution in Backdrop CMS
- UNIX symbolic link following in drupal7 (Alpine package)
- Gentoo update for PEAR Archive_Tar
- Arch Linux update for nextcloud
- Amazon Linux AMI update for php7-pear
- Debian update for php-pear
- SUSE update for php72
- SUSE update for php74-pear
- SUSE update for php7-pear
- Ubuntu update for php-pear
- Red Hat Enterprise Linux 8 update for the php:7.4 module
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the php:7.4 module
- Red Hat Enterprise Linux 7 update for php-pear
- Multiple vulnerabilities in Oracle Linux
- Fedora 33 update for php-pear
- Fedora 32 update for php-pear
- Fedora EPEL 7 update for drupal7
- Fedora 34 update for drupal7
- Fedora 35 update for drupal7
- Anolis OS update for php:7.4 module
- Anolis OS update for php-pear