UbuntuUpdates.org

Bugs fixes in "php-pear"

Origin Bug number Title Date fixed
CVE CVE-2021-32610 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ... 2021-07-29
CVE CVE-2021-32610 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ... 2021-07-29
CVE CVE-2021-32610 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ... 2021-07-29
CVE CVE-2021-32610 In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ... 2021-07-29
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue 2021-02-08
CVE CVE-2020-28949 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o 2020-12-01
CVE CVE-2020-28948 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. 2020-12-01
CVE CVE-2020-2894 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4 2020-12-01
CVE CVE-2020-28949 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o 2020-12-01
CVE CVE-2020-28948 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. 2020-12-01
CVE CVE-2020-2894 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4 2020-12-01
CVE CVE-2020-28949 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o 2020-12-01
CVE CVE-2020-28948 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. 2020-12-01
CVE CVE-2020-2894 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4 2020-12-01
CVE CVE-2020-28949 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o 2020-12-01



About   -   Send Feedback to @ubuntu_updates