CVE-2018-20783

Name
CVE-2018-20783
Description
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugs.php.net/bug.php?id=77143
Vendor Advisory http://php.net/ChangeLog-7.php
Vendor Advisory http://php.net/ChangeLog-5.php
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html
UBUNTU https://usn.ubuntu.com/3566-2/
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
REDHAT https://access.redhat.com/errata/RHSA-2019:2519
REDHAT https://access.redhat.com/errata/RHSA-2019:3299

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= None < 5.6.39
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.0.0 < 7.0.33
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.1.0 < 7.1.25
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.2.0 < 7.2.13

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
php7 edge-community 7.2.13-r0 None fixed