Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202006-14 ] PEAR Archive_Tar: Remote code execution vulnerability
Date: Mon, 15 Jun 2020 16:24:46
Message-Id: 20200615154637.GC17996@bubba
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202006-14
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: PEAR Archive_Tar: Remote code execution vulnerability
9 Date: June 15, 2020
10 Bugs: #675576
11 ID: 202006-14
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A buffer overflow in the PEAR module Archive_Tar might allow local or
19 remote attacker(s) to execute arbitrary code.
20
21 Background
22 ==========
23
24 This class provides handling of tar files in PHP.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 dev-php/PEAR-Archive_Tar
33 < 1.4.5 >= 1.4.5
34
35 Description
36 ===========
37
38 An issue was discovered in the PEAR module Archive_Tar's handling of
39 file paths within Tar achives.
40
41 Impact
42 ======
43
44 A local or remote attacker could possibly execute arbitrary code with
45 the privileges of the process.
46
47 Workaround
48 ==========
49
50 Avoid handling untrusted Tar files with this package until you have
51 upgraded to a non-vulnerable version.
52
53 Resolution
54 ==========
55
56 All PEAR-Archive_Tar users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=dev-php/PEAR-Archive_Tar-1.4.5"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2018-1000888
65 https://nvd.nist.gov/vuln/detail/CVE-2018-1000888
66
67 Availability
68 ============
69
70 This GLSA and any updates to it are available for viewing at
71 the Gentoo Security Website:
72
73 https://security.gentoo.org/glsa/202006-14
74
75 Concerns?
76 =========
77
78 Security is a primary focus of Gentoo Linux and ensuring the
79 confidentiality and security of our users' machines is of utmost
80 importance to us. Any security concerns should be addressed to
81 security@g.o or alternatively, you may file a bug at
82 https://bugs.gentoo.org.
83
84 License
85 =======
86
87 Copyright 2020 Gentoo Foundation, Inc; referenced text
88 belongs to its owner(s).
89
90 The contents of this document are licensed under the
91 Creative Commons - Attribution / Share Alike license.
92
93 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature