CVE-2018-20783

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may a… (CVE-2018-20783)

Description

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
92.5 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
5.7 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-02-21 19:00 UTC

Affected operating systems

  • linux

    opensuse / leap42.3

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • php

    php7.0.0 – 7.0.33

  • php

    php7.1.0 – 7.1.25

  • php

    php7.2.0 – 7.2.13

  • php

    php5.6.39

References & sources

IDCVE-2018-20783