CVE-2020-28949
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Archive_Tar library fails to properly block dangerous file operations when extracting archives. An attacker can use special filenames to overwrite existing files on the system during extraction.
Archive_Tar versions up to 1.4.10 implement incomplete filename sanitization that only blocks phar:// stream wrappers, leaving other protocols (e.g., file://) exploitable. During archive extraction, a crafted filename with stream wrapper syntax allows arbitrary file write/overwrite via path traversal. Requires user interaction to extract a malicious archive.
The full analysis of this CVE is available in Portuguese →