Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11147

Опубликовано: 10 июл. 2017
Источник: debian
EPSS Низкий

Описание

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.1fixed7.1.1-1package
php7.0fixed7.0.15-1package
php5removedpackage
php5fixed5.6.30+dfsg-0+deb8u1jessiepackage

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=73773

  • Fixed in 7.1.1, 7.0.15, 5.6.30

  • https://git.php.net/?p=php-src.git;a=commitdiff;h=e5246580a85f031e1a3b8064edbaa55c1643a451

  • http://openwall.com/lists/oss-security/2017/07/10/6

EPSS

Процентиль: 84%
0.02172
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 8 лет назад

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 6.5
redhat
больше 8 лет назад

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 9.1
nvd
почти 8 лет назад

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 9.1
github
около 3 лет назад

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 9.1
fstec
больше 8 лет назад

Уязвимость функции phar_parse_pharfile (ext/phar/phar.c) обработчика архивов PHAR, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02172
Низкий