CVE-2020-28949highunder attack

CVE-2020-28949

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 85%
from disclosure to weapon683 days
Published on NVDNov 19
1st PoC+683d
metasploitNov 17
CISA KEV+644d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (7 components)
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 6 · Red Hat Software Collections
no_fix_planned: Out of support scope
Fixed
4 products (606 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream EUS (v.8.4) · Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Workstation (v. 7)
Action required by CISAfederal deadline: 2022-09-15

Apply updates per vendor instructions.

In short

Archive_Tar library fails to properly block dangerous file operations when extracting archives. An attacker can use special filenames to overwrite existing files on the system during extraction.

Technical detail

Archive_Tar versions up to 1.4.10 implement incomplete filename sanitization that only blocks phar:// stream wrappers, leaving other protocols (e.g., file://) exploitable. During archive extraction, a crafted filename with stream wrapper syntax allows arbitrary file write/overwrite via path traversal. Requires user interaction to extract a malicious archive.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.