Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) Updated also Archive_Tar to 1.4.11. References: - https://bugs.mageia.org/show_bug.cgi?id=27664 . MGASA-2020-0453 - Updated php-pear packages fix security vulnerabilities Publication date: 08 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0453.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-28948, CVE-2020-28949 Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) Updated also Archive_Tar to 1.4.11. References: - https://bugs.mageia.org/show_bug.cgi?id=27664 - https://lists.debian.org/debian-lts-announce/2020/11/msg00043.html - https://lists.fedoraproject.org/archives/list/
* Fix Bug #27002: Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) [mrook]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f351eb14e3 2020-12-02 10:39:54.177827 --------------------------------------------------------------------------------Name : php-pear Product : Fedora 33 Version : 1.10.12 Release : 4.fc33 URL : https://pear.php.net/package/PEAR Summary : PHP Extension and Application Repository framework Description : PEAR is a framework and distribution system for reusable PHP components. This package contains the basic PEAR components. --------------------------------------------------------------------------------Update Information: * Fix Bug #27002: Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) [mrook] --------------------------------------------------------------------------------ChangeLog: * Mon Nov 23 2020 Remi Collet - 1:1.10.12-4 - update Archive_Tar to 1.4.11 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f351eb14e3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
* Fix Bug #27002: Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) [mrook]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-5271a896ff 2020-12-02 10:39:53.044367 --------------------------------------------------------------------------------Name : php-pear Product : Fedora 32 Version : 1.10.12 Release : 4.fc32 URL : https://pear.php.net/package/PEAR Summary : PHP Extension and Application Repository framework Description : PEAR is a framework and distribution system for reusable PHP components. This package contains the basic PEAR components. --------------------------------------------------------------------------------Update Information: * Fix Bug #27002: Filename manipulation vulnerabilities (CVE-2020-28948 / CVE-2020-28949) [mrook] --------------------------------------------------------------------------------ChangeLog: * Mon Nov 23 2020 Remi Collet - 1:1.10.12-4 - update Archive_Tar to 1.4.11 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-5271a896ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.