Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Important: perl-Archive-Tar security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:30857", "synopsis": "Important: perl-Archive-Tar security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for perl-Archive-Tar.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.\n\nSecurity Fix(es):\n\n* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2481314", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2481314", "description": ""}], "cves": [{"name": "CVE-2026-42496", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42496", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", "cvss3BaseScore": "8.2", "cwe": "CWE-22"}], "references": [], "publishedAt": "2026-07-05T12:05:09.130757Z", "rpms": {"Rocky Linux 10": {"nvras": ["perl-Archive-Tar-0:3.02-512.el10_2.1.noarch.rpm", "perl-Archive-Tar-0:3.02-512.el10_2.1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay informed about the perl-Archive-Tar security update affecting Rocky Linux with important vulnerability details and fixes.. Rocky Linux Security, Archive Tar Update, Important Security Advisory. .Severity: Important. LinuxSecurity.com Team
Important: perl-Archive-Tar security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:30856", "synopsis": "Important: perl-Archive-Tar security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for perl-Archive-Tar.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.\n\nSecurity Fix(es):\n\n* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2481314", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2481314", "description": ""}], "cves": [{"name": "CVE-2026-42496", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42496", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", "cvss3BaseScore": "8.2", "cwe": "CWE-22"}], "references": [], "publishedAt": "2026-07-01T12:03:26.775911Z", "rpms": {"Rocky Linux 9": {"nvras": ["perl-Archive-Tar-0:2.38-6.el9_8.1.noarch.rpm", "perl-Archive-Tar-0:2.38-6.el9_8.1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important perl-Archive-Tar security update for Rocky Linux 9 addresses path traversal issue. Stay safe with updates.. Rocky Linux, Archive Tar, security update, important patch, file access flaw. . Severity:Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-30856 http://linux.oracle.com/errata/ELSA-2026-30856.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: perl-Archive-Tar-2.38-6.el9_8.1.noarch.rpm aarch64: perl-Archive-Tar-2.38-6.el9_8.1.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/perl-Archive-Tar-2.38-6.el9_8.1.src.rpm Related CVEs: CVE-2026-42496 Description of changes: [2.38-6.1] - Fix CVE-2026-42496: validate symlink and hardlink targets in secure extract mode - Resolves: RHEL-181662 _______________________________________________ El-errata mailing list
Security update. Publication date: 24 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0230.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-42496, CVE-2026-42497, CVE-2026-9538 Description: The updated package fixes security vulnerabilities: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. (CVE-2026-42496) Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. (CVE-2026-42497) Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. (CVE-2026-9538) References: - https://bugs.mageia.org/show_bug.cgi?id=35587 - https://www.openwall.com/lists/oss-security/2026/05/26/2 - https://www.openwall.com/lists/oss-security/2026/05/26/3 - https://www.openwall.com/lists/oss-security/2026/05/26/4 - https://www.cve.org/CVERecord?id=CVE-2026-42496 - https://www.cve.org/CVERecord?id=CVE-2026-42497 - https://www.cve.org/CVERecord?id=CVE-2026-9538 SRPMS: - 9/core/perl-Archive-Tar-2.380.0-2.1.mga9 . Critical security update for Mageia addresses multiple vulnerabilities in Archive::Tar impacting version prior to 3.10.. Mageia security update, Archive::Tar vulnerabilities, critical patch, extraction security, memory attack mitigation. . Severity: Critical. LinuxSecurity.com Team
An update for the php:7.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: php:7.4 security update Advisory ID: RHSA-2022:6541-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:6541 Issue date: 2022-09-15 CVE Names: CVE-2020-28948 CVE-2020-28949 CVE-2020-36193 ==================================================================== 1. Summary: An update for the php:7.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked (CVE-2020-28948) * Archive_Tar: improper filename sanitization leads to file overwrites (CVE-2020-28949) * Archive_Tar: directory traversal due to inadequate checking of symbolic links (CVE-2020-36193) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1904001 - CVE-2020-28948 Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked 1910323 - CVE-2020-28949 Archive_Tar: improper filename sanitization leads to file overwrites 1942961 - CVE-2020-36193 Archive_Tar: directory traversal due to inadequate checking of symbolic links 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.4): Source: libzip-1.6.1-1.module+el8.3.0+6678+b09f589e.src.rpm php-7.4.6-5.module+el8.4.0+15727+276bb227.src.rpm php-pear-1.10.13-1.module+el8.4.0+16578+ed65e99e.src.rpm php-pecl-apcu-5.1.18-1.module+el8.3.0+6678+b09f589e.src.rpm php-pecl-rrd-2.0.1-1.module+el8.3.0+6678+b09f589e.src.rpm php-pecl-xdebug-2.9.5-1.module+el8.3.0+6678+b09f589e.src.rpm php-pecl-zip-1.18.2-1.module+el8.3.0+6678+b09f589e.src.rpm aarch64: libzip-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm libzip-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm libzip-debugsource-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm libzip-devel-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm libzip-tools-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm libzip-tools-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-bcmath-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-bcmath-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-cli-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-cli-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-common-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-common-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-dba-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-dba-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-dbg-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-dbg-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-debugsource-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-devel-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-embedded-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-embedded-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-enchant-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-enchant-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-ffi-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-ffi-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-fpm-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-fpm-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-gd-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-gd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-gmp-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-gmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-intl-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-intl-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-json-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-json-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-ldap-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-ldap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-mbstring-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-mbstring-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-mysqlnd-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-mysqlnd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-odbc-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-odbc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-opcache-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-opcache-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-pdo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-pdo-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-pecl-apcu-5.1.18-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-apcu-debuginfo-5.1.18-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-apcu-debugsource-5.1.18-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-apcu-devel-5.1.18-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-rrd-2.0.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-rrd-debuginfo-2.0.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-rrd-debugsource-2.0.1-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-xdebug-2.9.5-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-xdebug-debuginfo-2.9.5-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-xdebug-debugsource-2.9.5-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-zip-1.18.2-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-zip-debuginfo-1.18.2-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pecl-zip-debugsource-1.18.2-1.module+el8.3.0+6678+b09f589e.aarch64.rpm php-pgsql-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-pgsql-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-process-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-process-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-snmp-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-snmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-soap-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-soap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-xml-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-xml-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-xmlrpc-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm php-xmlrpc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.aarch64.rpm noarch: apcu-panel-5.1.18-1.module+el8.3.0+6678+b09f589e.noarch.rpm php-pear-1.10.13-1.module+el8.4.0+16578+ed65e99e.noarch.rpm ppc64le: libzip-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm libzip-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm libzip-debugsource-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm libzip-devel-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm libzip-tools-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm libzip-tools-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-bcmath-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-bcmath-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-cli-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-cli-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-common-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-common-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-dba-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-dba-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-dbg-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-dbg-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-debugsource-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-devel-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-embedded-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-embedded-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-enchant-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-enchant-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-ffi-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-ffi-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-fpm-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-fpm-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-gd-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-gd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-gmp-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-gmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-intl-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-intl-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-json-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-json-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-ldap-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-ldap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-mbstring-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-mbstring-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-mysqlnd-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-mysqlnd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-odbc-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-odbc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-opcache-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-opcache-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-pdo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-pdo-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-pecl-apcu-5.1.18-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-apcu-debuginfo-5.1.18-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-apcu-debugsource-5.1.18-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-apcu-devel-5.1.18-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-rrd-2.0.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-rrd-debuginfo-2.0.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-rrd-debugsource-2.0.1-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-xdebug-2.9.5-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-xdebug-debuginfo-2.9.5-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-xdebug-debugsource-2.9.5-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-zip-1.18.2-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-zip-debuginfo-1.18.2-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pecl-zip-debugsource-1.18.2-1.module+el8.3.0+6678+b09f589e.ppc64le.rpm php-pgsql-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-pgsql-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-process-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-process-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-snmp-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-snmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-soap-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-soap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-xml-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-xml-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-xmlrpc-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm php-xmlrpc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.ppc64le.rpm s390x: libzip-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm libzip-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm libzip-debugsource-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm libzip-devel-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm libzip-tools-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm libzip-tools-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-bcmath-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-bcmath-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-cli-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-cli-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-common-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-common-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-dba-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-dba-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-dbg-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-dbg-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-debugsource-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-devel-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-embedded-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-embedded-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-enchant-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-enchant-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-ffi-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-ffi-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-fpm-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-fpm-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-gd-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-gd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-gmp-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-gmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-intl-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-intl-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-json-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-json-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-ldap-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-ldap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-mbstring-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-mbstring-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-mysqlnd-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-mysqlnd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-odbc-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-odbc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-opcache-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-opcache-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-pdo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-pdo-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-pecl-apcu-5.1.18-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-apcu-debuginfo-5.1.18-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-apcu-debugsource-5.1.18-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-apcu-devel-5.1.18-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-rrd-2.0.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-rrd-debuginfo-2.0.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-rrd-debugsource-2.0.1-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-xdebug-2.9.5-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-xdebug-debuginfo-2.9.5-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-xdebug-debugsource-2.9.5-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-zip-1.18.2-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-zip-debuginfo-1.18.2-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pecl-zip-debugsource-1.18.2-1.module+el8.3.0+6678+b09f589e.s390x.rpm php-pgsql-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-pgsql-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-process-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-process-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-snmp-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-snmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-soap-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-soap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-xml-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-xml-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-xmlrpc-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm php-xmlrpc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.s390x.rpm x86_64: libzip-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm libzip-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm libzip-debugsource-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm libzip-devel-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm libzip-tools-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm libzip-tools-debuginfo-1.6.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-bcmath-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-bcmath-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-cli-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-cli-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-common-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-common-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-dba-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-dba-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-dbg-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-dbg-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-debugsource-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-devel-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-embedded-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-embedded-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-enchant-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-enchant-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-ffi-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-ffi-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-fpm-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-fpm-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-gd-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-gd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-gmp-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-gmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-intl-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-intl-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-json-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-json-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-ldap-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-ldap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-mbstring-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-mbstring-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-mysqlnd-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-mysqlnd-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-odbc-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-odbc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-opcache-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-opcache-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-pdo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-pdo-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-pecl-apcu-5.1.18-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-apcu-debuginfo-5.1.18-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-apcu-debugsource-5.1.18-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-apcu-devel-5.1.18-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-rrd-2.0.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-rrd-debuginfo-2.0.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-rrd-debugsource-2.0.1-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-xdebug-2.9.5-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-xdebug-debuginfo-2.9.5-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-xdebug-debugsource-2.9.5-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-zip-1.18.2-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-zip-debuginfo-1.18.2-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pecl-zip-debugsource-1.18.2-1.module+el8.3.0+6678+b09f589e.x86_64.rpm php-pgsql-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-pgsql-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-process-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-process-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-snmp-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-snmp-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-soap-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-soap-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-xml-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-xml-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-xmlrpc-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm php-xmlrpc-debuginfo-7.4.6-5.module+el8.4.0+15727+276bb227.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-28948 https://access.redhat.com/security/cve/CVE-2020-28949 https://access.redhat.com/security/cve/CVE-2020-36193 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYyWNodzjgjWX9erEAQhW7Q//V7Hol4et6Ohc7tyFxWOGeWYxA43Qchg7 baSBgUyy0D23qNCMEd6KoN2eLHK/bPQBGLfK8qv4kp8gYeBQaVxe2d8RGX0v75Ys wNlxP3P8dAee7QxyKJpcUUg17nsqix2yV5ONjQaIbY9MVW555+DvTzwGIjy5WCrK Ji60NQ9TOOwsT9+CfFe+NmVeyndge6n75iXNCGd+Xxp4KxE1YDgHq+xx6svrw6gM Tbm0W9NSwR46bbuwaCFcGe2XIW+GufVPzDKP4a253aTzI3Xg6GaAvQuVUAoeo2/P IwICX0ls1GKhc6Tl5qY9mPIM+MKksULAi214L4imY3AiN9v9hv2y6ftLEIZ3MxH/ VW3iKybNwpd0rx2X1j+TQwH80EHZmrSUUjfvMXb92Q46bO/JJBMVkt8PuX6j0a1s h+sYSQvr+XT0lNoUrN4txlXIQXXZy1SfJ19gcm+KqiNIg1nma0UKU8ISn288hF4O dxuQNy8egL5tF6lkr4CJiLAHfF7r8f5JUR+re7yfT5rlXGDhWOgIWByUrrV/XFnn QO0iVLoWTjqXTgNw9C2nTXO5lSfthRFXZR2Zi1+bvmzKNzaU4P8VoOS7eUy9sf9k LYj6ntasSYM9P/q5tMyM+/tepQ9SQYMqeMqhYbzG+tQ9lkqQfigwa8dpjnvVnw+i Wb+/j9KqbcM=txgG -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. The vulnerability is mitigated by the fact that Drupal core's use of . ------------------------------------------------------------------------- Debian LTS Advisory DLA-2721-1
perl: Directory traversal in Archive::Tar (CVE-2018-12015) SL7 x86_64 perl-Archive-Tar-1.92-3.el7.noarch.rpm noarch perl-Archive-Tar-1.92-3.el7.noarch.rpm - Scientific Linux Development Team. Synopsis: Moderate: perl-Archive-Tar security update Advisory ID: SLSA-2019:2097-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-12015 -- Security Fix(es): * perl: Directory traversal in Archive::Tar (CVE-2018-12015) -- SL7 x86_64 perl-Archive-Tar-1.92-3.el7.noarch.rpm noarch perl-Archive-Tar-1.92-3.el7.noarch.rpm - Scientific Linux Development Team . This advisory highlights the critical update of perl-Archive-Tar on Scientific Linux SL7 due to a severe directory traversal vulnerability that demands immediate action. perl Archive Tar, directory traversal, Scientific Linux advisory, security update, Software Fix. . LinuxSecurity.com Team
Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4226-1
Get the latest Linux and open source security news straight to your inbox.