• [SECURITY] [DSA 4894-1] php-pear security update

    From Salvatore Bonaccorso@21:1/5 to All on Tue Apr 20 20:20:02 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4894-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso
    April 20, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : php-pear
    CVE ID : CVE-2020-36193
    Debian Bug : 980428

    It was discovered that the PEAR Archive_Tar package for handling tar
    files in PHP is prone to a directory traversal flaw due to inadequate
    checking of symbolic links.

    For the stable distribution (buster), this problem has been fixed in
    version 1:1.10.6+submodules+notgz-1.1+deb10u2.

    We recommend that you upgrade your php-pear packages.

    For the detailed security status of php-pear please refer to its
    security tracker page at:
    https://security-tracker.debian.org/tracker/php-pear

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmB/GWhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SxVQ/+JSiE9k83A0aMfRuKnIMnCBtwNdUgBD+a32rAYcBh/MbuaQfOWGHgybVJ VG3f4sFeo++0nOLlDxT9cFYqPDyS7Vv4SocLFSp6UDDuUS+Dm6FjrFfS1Q57FAPp oXuCBRhrEI5/7iAgiTDYVIFkbcByRyl6Xcf8AqpzhHCVikEZ2bKv8DJq8GD/2Gyq 5oUS7V6/2DosMHFhfWUj7HzQoovM1gbx8TaCdRHtEx6BSRBwt9uEioygnQ3JGDAq /tTGUm4GSVMGjBXhVYccKP+RElNtRv0Gx4I23gTSg13l4rtbT9NZITQXrF35eT3x Ag8W2BmaOTc4wrMz/CYLV/GcScCzbT+ZLBcH2pK2PaAAn9keK0Ci4cuupTCGG3Fh lXSwt1mBxibDYR9aIvqyqtgjG7Zyd44lWgz0YZCurIuPACqlHEzKX8iZ0k+/ck/v B5vI0A6NDp2aMXNNF09CRKo+8zv9ZzgXWW2VWIoKwSjvQ6/KeFwcBIkKQAAUWb77 ydY72V9m258JDf/uA3onCClvu5gGiKRv9Xr9MYJD8biwB/kguqYSJtjzE6XuXVZI /y6RrMbZIJDirLkNni5NH2aP28PpBr0F155QXpNU9Xn4tD93+7ogie09+pydaS4b 5JA00tRbgGAynfAXR3R2nKZTk6FCQd5QQxTBy/XpIZYbNgsfakk=
    =Fe7A
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)