[ GLSA 202006-14 ] PEAR Archive_Tar: Remote code execution vulnerability

Aaron Bauman <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <20200615154637.GC17996@bubba>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202006-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: PEAR Archive_Tar: Remote code execution vulnerability
     Date: June 15, 2020
     Bugs: #675576
       ID: 202006-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A buffer overflow in the PEAR module Archive_Tar might allow local or
remote attacker(s) to execute arbitrary code.

Background
==========

This class provides handling of tar files in PHP.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-php/PEAR-Archive_Tar
                                  < 1.4.5                    >= 1.4.5 

Description
===========

An issue was discovered in the PEAR module Archive_Tar's handling of
file paths within Tar achives.

Impact
======

A local or remote attacker could possibly execute arbitrary code with
the privileges of the process.

Workaround
==========

Avoid handling untrusted Tar files with this package until you have
upgraded to a non-vulnerable version.

Resolution
==========

All PEAR-Archive_Tar users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-php/PEAR-Archive_Tar-1.4.5"

References
==========

[ 1 ] CVE-2018-1000888
      https://nvd.nist.gov/vuln/detail/CVE-2018-1000888

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202006-14

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2020 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEEDA48qNrrn8VVVcst4yp5f7HQy3AFAl7nl90ACgkQ4yp5f7HQ
y3C9Xgf+M5nAFJLQDrwMwwQ9E1dudWJW/0jYJ2TOmcKvi9aDfxn/H11CHQ9Bhdg5
6OBk/7Qk+4zpxdWm8k3KJM+EGyAv67N+gBnabpCxY5IC+XgWhSnW2Dwb4hlYhgwC
smCYY9b72ERtT7o1joOgx8K+SFqW+ifvrpCi9mO0ahPaupKpZQC8oMf5oZbALgi9
LQNfk3CnaNOx7a8GCE1LdEKyEDmRLfVlzr3ing6EmA5fRjPrb27IUYuD0S6gWG8G
pwbV1QleIof2MZtCvMJ7OccOLWi1LYFUsfa3AuMr4LEmr8xRnzJXI2IVzdva24N8
jqtOErxKLn7JM0vI+jrVsc4ZFJw/8w==
=qyyb
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.