CVE-2017-11147

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.
References
Link Resource
https://bugs.php.net/bug.php?id=73773 Exploit Issue Tracking Vendor Advisory
http://php.net/ChangeLog-7.php Release Notes Vendor Advisory
http://php.net/ChangeLog-5.php Release Notes Vendor Advisory
http://openwall.com/lists/oss-security/2017/07/10/6 Mailing List Patch Third Party Advisory
http://git.php.net/?p=php-src.git;a=commit;h=e5246580a85f031e1a3b8064edbaa55c1643a451 Broken Link Mailing List Vendor Advisory
http://www.securityfocus.com/bid/99607 Third Party Advisory VDB Entry
https://www.tenable.com/security/tns-2017-12 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180112-0001/ Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1296 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*

Information

Published : 2017-07-10 07:29

Updated : 2022-07-20 10:56


NVD link : CVE-2017-11147

Mitre link : CVE-2017-11147


JSON object : View

CWE
CWE-125

Out-of-bounds Read

Advertisement

dedicated server usa

Products Affected

netapp

  • clustered_data_ontap

php

  • php