Junglewise Threat Intelligence

CVE-2020-28949: PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

CVE-2020-28949 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-08-25

Executive brief

PEAR Archive_Tar through 1.4.10 fails to properly sanitize stream wrappers in filenames, allowing for deserialization of untrusted data. While it blocks the 'phar:' wrapper, it fails to account for case variations like 'PHAR:' or other wrappers like 'file:', which can lead to arbitrary file overwrites or remote code execution.

Affected products

  • PEAR Archive_Tar through 1.4.10

Timeline

  • 2020-11-17: disclosed: Initial Debian LTS advisory date (approximate based on mailing list)
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats