Описание
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Отчет
PHP 7.2 and 7.3 marked End of Life at the time this CVE was released. There would be no patches made available for php-pear.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | php-pear | Out of support scope | ||
Red Hat Enterprise Linux 8 | php:7.2/php-pear | Will not fix | ||
Red Hat Enterprise Linux 8 | php:7.3/php-pear | Will not fix | ||
Red Hat Software Collections | rh-php73-php-pear | Will not fix | ||
Red Hat Enterprise Linux 7 | php-pear | Fixed | RHSA-2022:7340 | 02.11.2022 |
Red Hat Enterprise Linux 8 | php | Fixed | RHSA-2022:6542 | 15.09.2022 |
Red Hat Enterprise Linux 8.4 Extended Update Support | php | Fixed | RHSA-2022:6541 | 15.09.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Archive_Tar through 1.4.10 allows an unserialization attack because ph ...
Deserialization of Untrusted Data in Archive_Tar
Уязвимость функции _maliciousFilename класса Archive_Tar библиотеки PHP классов PEAR, позволяющая нарушителю выполнить произвольный PHP-код
EPSS
7.8 High
CVSS3