HIGH

CVE-2018-1000888

CVSS v3

8.8

HIGH

EPSS Score

29.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.

Technical details

Published
12/28/2018

Frequently asked questions

What is CVE-2018-1000888?

PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.

Is CVE-2018-1000888 actively exploited?

Active exploitation of CVE-2018-1000888 has not been confirmed. The EPSS score is 29.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-1000888?

CVE-2018-1000888 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2018-1000888 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.