Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc9g-5348-gqwv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.6

Описание

In PHP versions 7.2.x below 7.3.21, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

In PHP versions 7.2.x below 7.3.21, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

EPSS

Процентиль: 62%
0.00425
Низкий

3.6 Low

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 3.6
redhat
больше 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
nvd
больше 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
debian
больше 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below ...

suse-cvrf
больше 5 лет назад

Security update for php7

EPSS

Процентиль: 62%
0.00425
Низкий

3.6 Low

CVSS3

Дефекты

CWE-416