CVE-2016-10160

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
References
Link Resource
http://php.net/ChangeLog-5.php Release Notes Vendor Advisory
http://php.net/ChangeLog-7.php Release Notes Vendor Advisory
http://www.debian.org/security/2017/dsa-3783 Third Party Advisory
http://www.securityfocus.com/bid/95783 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037659 Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:1296 Third Party Advisory
https://bugs.php.net/bug.php?id=73768 Issue Tracking Patch Vendor Advisory
https://github.com/php/php-src/commit/b28b8b2fee6dfa6fcd13305c581bb835689ac3be Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/201702-29 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180112-0001/ Third Party Advisory
https://www.tenable.com/security/tns-2017-04 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-01-24 21:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-10160

Mitre link : CVE-2016-10160

CVE.ORG link : CVE-2016-10160


JSON object : View

Products Affected

php

  • php

netapp

  • clustered_data_ontap

debian

  • debian_linux
CWE
CWE-193

Off-by-one Error