In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
2020-02-27T21:15:18.927
2024-11-21T05:36:35.560
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | ≤ 7.2.27 | Yes |
Application | php | php | ≤ 7.3.14 | Yes |
Application | php | php | ≤ 7.4.2 | Yes |
Operating System | microsoft | windows | - | No |
Application | tenable | tenable.sc | < 5.19.0 | Yes |