In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php7 | Oct 1, 2024 | Feb 27, 2020 |
| Amazon_linux | — | Upgrade php73Upgrade php72 | Mar 14, 2020 | Feb 27, 2020 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Mar 27, 2020 | Feb 27, 2020 |
| Oracle Solaris | — | Upgrade web/php-73 to version 7.3.15-11.4.20.0.1.4.0 on Solaris 11.4Upgrade web/php-74 to version 7.4.3-11.4.21.0.1.69.0 on Solaris 11.4 | Jan 19, 2021 | Feb 27, 2020 |
| Php | — | Upgrade to PHP version 7.4.3Upgrade to PHP version 7.3.15 | Apr 6, 2020 | Feb 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub