VYPR
High severityCISA KEVNVD Advisory· Published Nov 19, 2020· Updated Oct 21, 2025

CVE-2020-28949

CVE-2020-28949

Description

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pear/archive_tarPackagist
< 1.4.111.4.11

Affected products

40

Patches

Vulnerability mechanics

References

29

News mentions

0

No linked articles in our index yet.