Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc9g-5348-gqwv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.6

Описание

In PHP versions 7.2.x below 7.3.21, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

In PHP versions 7.2.x below 7.3.21, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

EPSS

Процентиль: 78%
0.01156
Низкий

3.6 Low

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 3.6
redhat
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
nvd
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
debian
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below ...

suse-cvrf
почти 5 лет назад

Security update for php7

EPSS

Процентиль: 78%
0.01156
Низкий

3.6 Low

CVSS3

Дефекты

CWE-416