Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2020-28949

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-74

Beschrijving NL

PEAR Archive_Tar staat een unserialization-aanval toe omdat phar: is geblokkeerd, maar PHAR: is niet geblokkeerd. PEAR staat voor PHP Extension and Application Repository en is een open-source framework en distributiesysteem voor herbruikbare PHP-componenten met bekend gebruik in producten van derden zoals Drupal Core en Red Hat Linux.

Vereiste actie: voer updates uit volgens de instructies van de leverancier.

Origineel (Engels) tonen

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

Required action: Apply updates per vendor instructions.

Vendors

Pear

Affected products

Archive_tar

References