CVE-2020-28949
Beschrijving NL
PEAR Archive_Tar staat een unserialization-aanval toe omdat phar: is geblokkeerd, maar PHAR: is niet geblokkeerd. PEAR staat voor PHP Extension and Application Repository en is een open-source framework en distributiesysteem voor herbruikbare PHP-componenten met bekend gebruik in producten van derden zoals Drupal Core en Red Hat Linux.
Vereiste actie: voer updates uit volgens de instructies van de leverancier.
Origineel (Engels) tonen
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Required action: Apply updates per vendor instructions.