PT-2019-12515 · Php · Pharstreamwrapper

Tom Klingenberg

·

Publicado

2019-05-09

·

Atualizado

2022-05-24

·

CVE-2019-11830

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PharStreamWrapper package versions 2.x before 2.1.1 PharStreamWrapper package versions 3.x before 3.1.1
Description The PharMetaDataInterceptor in the PharStreamWrapper package mishandles Phar stub parsing, allowing attackers to bypass a deserialization protection mechanism.
Recommendations For PharStreamWrapper package versions 2.x before 2.1.1, update to version 2.1.1 or later. For PharStreamWrapper package versions 3.x before 3.1.1, update to version 3.1.1 or later.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11830
GHSA-3HXW-G85P-QGXM

Produtos afetados

Pharstreamwrapper