-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4894-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 20, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-pear CVE ID : CVE-2020-36193 Debian Bug : 980428 It was discovered that the PEAR Archive_Tar package for handling tar files in PHP is prone to a directory traversal flaw due to inadequate checking of symbolic links. For the stable distribution (buster), this problem has been fixed in version 1:1.10.6+submodules+notgz-1.1+deb10u2. We recommend that you upgrade your php-pear packages. For the detailed security status of php-pear please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-pear Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmB/GWhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SxVQ/+JSiE9k83A0aMfRuKnIMnCBtwNdUgBD+a32rAYcBh/MbuaQfOWGHgybVJ VG3f4sFeo++0nOLlDxT9cFYqPDyS7Vv4SocLFSp6UDDuUS+Dm6FjrFfS1Q57FAPp oXuCBRhrEI5/7iAgiTDYVIFkbcByRyl6Xcf8AqpzhHCVikEZ2bKv8DJq8GD/2Gyq 5oUS7V6/2DosMHFhfWUj7HzQoovM1gbx8TaCdRHtEx6BSRBwt9uEioygnQ3JGDAq /tTGUm4GSVMGjBXhVYccKP+RElNtRv0Gx4I23gTSg13l4rtbT9NZITQXrF35eT3x Ag8W2BmaOTc4wrMz/CYLV/GcScCzbT+ZLBcH2pK2PaAAn9keK0Ci4cuupTCGG3Fh lXSwt1mBxibDYR9aIvqyqtgjG7Zyd44lWgz0YZCurIuPACqlHEzKX8iZ0k+/ck/v B5vI0A6NDp2aMXNNF09CRKo+8zv9ZzgXWW2VWIoKwSjvQ6/KeFwcBIkKQAAUWb77 ydY72V9m258JDf/uA3onCClvu5gGiKRv9Xr9MYJD8biwB/kguqYSJtjzE6XuXVZI /y6RrMbZIJDirLkNni5NH2aP28PpBr0F155QXpNU9Xn4tD93+7ogie09+pydaS4b 5JA00tRbgGAynfAXR3R2nKZTk6FCQd5QQxTBy/XpIZYbNgsfakk= =Fe7A -----END PGP SIGNATURE-----