CVE-2016-3142: Buffer Overflow
The pharparsezipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-3142?
CVE-2016-3142 is a vulnerability in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19.
How severe is CVE-2016-3142?
CVE-2016-3142 has a severity rating of 8.2 (high).
How can I exploit CVE-2016-3142?
CVE-2016-3142 can be exploited by placing a PK\x05\x06 signature at an invalid index to obtain sensitive information or cause a denial of service.
How can I fix CVE-2016-3142?
To fix CVE-2016-3142, update the PHP version to 5.5.33 or 5.6.19 or higher.
Where can I find more information about CVE-2016-3142?
You can find more information about CVE-2016-3142 at the following references: [link1], [link2], [link3].