First published: Sun May 22 2016(Updated: )
Fixed bug (Uninitialized pointer in phar_make_dirstream()). (CVE-2016-4343)
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | <7.0.3 | 7.0.3 |
debian/php5 | ||
debian/php7.0 | ||
PHP PHP | <5.5.36 | |
PHP PHP | >=5.6.0<5.6.18 | |
PHP PHP | >=7.0.0<7.0.3 | |
openSUSE openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this bug is CVE-2016-4343.
The severity of CVE-2016-4343 is high with a severity value of 8.8.
Versions of PHP before 5.6.18 and 7.x before 7.0.3 are affected by CVE-2016-4343.
Remote attackers can exploit CVE-2016-4343 by crafting a TAR archive file with zero-size ././@LongLink files.
You can find more information about CVE-2016-4343 in the PHP.net ChangeLog-7.php and the Openwall OSS Security mailing list.