Description
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28195 | In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash. |
References
History
No history.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T01:21:01.352Z
Reserved: 2020-01-15T00:00:00.000Z
Link: CVE-2020-7061
No data.
Status : Modified
Published: 2020-02-27T21:15:18.927
Modified: 2024-11-21T05:36:35.560
Link: CVE-2020-7061
OpenCVE Enrichment
No data.
EUVD