CVE-2020-28949
PEAR Archive_Tar
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
- CVSS
- 7.8
- EPSS
- 84.6% 99.7% percentile
- CISA KEV
- Listed
- Published
- 2020.11.20