Executive brief
PEAR Archive_Tar through 1.4.10 fails to properly sanitize stream wrappers in filenames, allowing for deserialization of untrusted data. While it blocks the 'phar:' wrapper, it fails to account for case variations like 'PHAR:' or other wrappers like 'file:', which can lead to arbitrary file overwrites or remote code execution.
Affected products
- PEAR Archive_Tar through 1.4.10
Timeline
- 2020-11-17: disclosed: Initial Debian LTS advisory date (approximate based on mailing list)
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog