CVE-2019-9675: Buffer Overflow
DISPUTED An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phartarwriteheadersint in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-9675.
What is the severity level of CVE-2019-9675?
CVE-2019-9675 has a severity level of high.
What versions of PHP are affected by CVE-2019-9675?
Versions of PHP before 7.1.27 and 7.3.x before 7.3.3 are affected by CVE-2019-9675.
How can I fix the CVE-2019-9675 vulnerability?
To fix the CVE-2019-9675 vulnerability, you should update PHP to version 7.1.27 or higher for PHP 7.x and to version 7.3.3 or higher for PHP 7.3.x.
Are there any references available for CVE-2019-9675?
Yes, you can find references for CVE-2019-9675 at the following links: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html).