In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.
2023-08-11T06:15:10.560
2025-02-13T17:16:59.457
Modified
CVSSv3.1: 9.4 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 8.0.30 | Yes |
Application | php | php | < 8.1.22 | Yes |
Application | php | php | < 8.2.9 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |