Lucene search

K
amazonAmazonALAS-2021-1481
HistoryFeb 16, 2021 - 12:13 a.m.

Medium: php7-pear

2021-02-1600:13:00
alas.aws.amazon.com
18

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.882 High

EPSS

Percentile

98.7%

Issue Overview:

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links. (cve-2020-36193)

Affected Packages:

php7-pear

Issue Correction:
Run yum update php7-pear to update your system.

New Packages:

noarch:  
    php7-pear-1.10.12-5.32.amzn1.noarch  
  
src:  
    php7-pear-1.10.12-5.32.amzn1.src  

Additional References

Red Hat: CVE-2020-36193

Mitre: CVE-2020-36193

OSVersionArchitecturePackageVersionFilename
Amazon Linux1noarchphp7-pear< 1.10.12-5.32.amzn1php7-pear-1.10.12-5.32.amzn1.noarch.rpm

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.882 High

EPSS

Percentile

98.7%