heap-based buffer overflow in phar_extract_file

Publication Date2020-01-26
TypeInformation Disclosure
Affected PHP Versions
  • 7.3.0 - 7.3.14
  • 7.4.0 - 7.4.2

CVE Details

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using the phar extension, certain content inside a PHAR file could lead to reading one-byte past the allocated buffer. This could potentially lead to information disclosure or crash.


Upgrade to PHP 7.3.15 or higher, or 7.4.3 or higher.