In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: php
Published: 2020-02-27T20:25:15.606064Z
Updated: 2024-09-16T16:49:14.274Z
Reserved: 2020-01-15T00:00:00
Link: CVE-2020-7063
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-27T21:15:19.117
Modified: 2024-11-21T05:36:35.850
Link: CVE-2020-7063
Redhat