CVE-2018-1000888
php-pear - security update
描述
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.
如何修補 CVE-2018-1000888
要修補 CVE-2018-1000888,請將受影響套件升級到下列已修補版本。
- —升級至 1:1.10.6+submodules+notgz-1.1 或更新版本
- —升級至 1:1.10.1+submodules+notgz-9+deb9u1 或更新版本
- —升級至 5.6.39+dfsg-0+deb8u2 或更新版本
- —升級至 1.4.4 或更新版本
CVE-2018-1000888 正在被利用嗎?
中等 — EPSS 為 18.3%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 1:1.10.6+submodules+notgz-1.1
- from 0, < 1:1.10.1+submodules+notgz-9+deb9u1
- from 0, < 5.6.39+dfsg-0+deb8u2
- from 0, < 1.4.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |