Files added to tar with Phar::buildFromIterator have all-access permissions
Published Feb 27, 2020
5.5
MEDIUMCVSS 3.1
EPSS 1.59%
Description
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.
Affected products
-
- Version 7.2.xStatusaffectedConstraints<7.2.28
- Version 7.3.xStatusaffectedConstraints<7.3.15
- Version 7.4.xStatusaffectedConstraints<7.4.3
- Version
Configuration 1
Configuration 2
- < 5.19.0
Configuration 3
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 8
php:7.3-8020020200715124551.ceb1cf90
Fixed · RHSA-2020:3662
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php73-php-0:7.3.20-1.el7
Fixed · RHSA-2020:5275
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php73-php-0:7.3.20-1.el7
Fixed · RHSA-2020:5275
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php73-php-0:7.3.20-1.el7
Fixed · RHSA-2020:5275
Red Hat Enterprise Linux 5
php
Out of support scope
Red Hat Enterprise Linux 5
php53
Out of support scope
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
php
Will not fix
Red Hat Enterprise Linux 8
php:7.2/php
Will not fix
Red Hat Software Collections
rh-php72-php
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.3-8020020200715124551.ceb1cf90 | Fixed | RHSA-2020:3662 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php73-php-0:7.3.20-1.el7 | Fixed | RHSA-2020:5275 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php73-php-0:7.3.20-1.el7 | Fixed | RHSA-2020:5275 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php73-php-0:7.3.20-1.el7 | Fixed | RHSA-2020:5275 |
| Red Hat Enterprise Linux 5 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | php53 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | php:7.2/php | Will not fix | n/a |
| Red Hat Software Collections | rh-php72-php | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Use different Phar class functions to compose the archive, such as addFile(), or reset file permissions upon extracting files from the archive.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-7063 Vendor Advisory
- https://bugs.php.net/bug.php?id=79082 x_refsource_MISCExploitVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1808536 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/03/msg00034.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7063
- https://security.gentoo.org/glsa/202003-57 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4330-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7063
- https://www.debian.org/security/2020/dsa-4717 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2020/dsa-4719 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRMPatchThird Party Advisory
Change history (0)
No recorded changes yet.