vulnerability

SUSE: CVE-2020-36193: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jan 18, 2021
Added
Aug 31, 2021
Modified
Aug 26, 2022

Description

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

Solution(s)

suse-upgrade-apache2-mod_php72suse-upgrade-php7-pearsuse-upgrade-php7-peclsuse-upgrade-php7-wddxsuse-upgrade-php72suse-upgrade-php72-bcmathsuse-upgrade-php72-bz2suse-upgrade-php72-calendarsuse-upgrade-php72-ctypesuse-upgrade-php72-curlsuse-upgrade-php72-dbasuse-upgrade-php72-develsuse-upgrade-php72-domsuse-upgrade-php72-enchantsuse-upgrade-php72-exifsuse-upgrade-php72-fastcgisuse-upgrade-php72-fileinfosuse-upgrade-php72-fpmsuse-upgrade-php72-ftpsuse-upgrade-php72-gdsuse-upgrade-php72-gettextsuse-upgrade-php72-gmpsuse-upgrade-php72-iconvsuse-upgrade-php72-imapsuse-upgrade-php72-intlsuse-upgrade-php72-jsonsuse-upgrade-php72-ldapsuse-upgrade-php72-mbstringsuse-upgrade-php72-mysqlsuse-upgrade-php72-odbcsuse-upgrade-php72-opcachesuse-upgrade-php72-opensslsuse-upgrade-php72-pcntlsuse-upgrade-php72-pdosuse-upgrade-php72-pearsuse-upgrade-php72-pear-archive_tarsuse-upgrade-php72-pgsqlsuse-upgrade-php72-pharsuse-upgrade-php72-posixsuse-upgrade-php72-pspellsuse-upgrade-php72-readlinesuse-upgrade-php72-shmopsuse-upgrade-php72-snmpsuse-upgrade-php72-soapsuse-upgrade-php72-socketssuse-upgrade-php72-sodiumsuse-upgrade-php72-sqlitesuse-upgrade-php72-sysvmsgsuse-upgrade-php72-sysvsemsuse-upgrade-php72-sysvshmsuse-upgrade-php72-tidysuse-upgrade-php72-tokenizersuse-upgrade-php72-wddxsuse-upgrade-php72-xmlreadersuse-upgrade-php72-xmlrpcsuse-upgrade-php72-xmlwritersuse-upgrade-php72-xslsuse-upgrade-php72-zipsuse-upgrade-php72-zlibsuse-upgrade-php74-pearsuse-upgrade-php74-pecl
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.