Description
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.
Published: 2020-02-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Use different Phar class functions to compose the archive, such as addFile(), or reset file permissions upon extracting files from the archive.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2160-1 php5 security update
Debian DSA Debian DSA DSA-4717-1 php7.0 security update
Debian DSA Debian DSA DSA-4719-1 php7.3 security update
EUVD EUVD EUVD-2020-28197 In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.
Ubuntu USN Ubuntu USN USN-4330-1 PHP vulnerabilities
History

No history.

Subscriptions

Debian Debian Linux
Opensuse Leap
Php Php
Redhat Enterprise Linux Rhel Software Collections
Tenable Tenable.sc
cve-icon MITRE

Status: PUBLISHED

Assigner: php

Published:

Updated: 2024-09-16T16:49:14.274Z

Reserved: 2020-01-15T00:00:00.000Z

Link: CVE-2020-7063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-27T21:15:19.117

Modified: 2024-11-21T05:36:35.850

Link: CVE-2020-7063

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-01-08T00:00:00Z

Links: CVE-2020-7063 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses