PT-2017-4183 · Php+3 · Php+3

Eyal Itkin

·

Published

2017-01-24

·

Updated

2022-08-29

·

CVE-2016-10159

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.30 PHP versions 7.0.x prior to 7.0.15
Description The issue is caused by an integer overflow in the phar parse pharfile function, allowing remote attackers to cause a denial of service, potentially leading to memory consumption or application crash, via a truncated manifest entry in a PHAR archive.
Recommendations For PHP versions prior to 5.6.30, update to version 5.6.30 or later. For PHP versions 7.0.x prior to 7.0.15, update to version 7.0.15 or later.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1114
BDU:2022-02549
CVE-2016-10159
DLA-818-1
DSA-3783-1
MGASA-2017-0040
OPENSUSE-SU-2017_0588-1
RHSA-2018:1296
SUSE-SU-2017:0534-1
SUSE-SU-2017:0556-1
SUSE-SU-2017:0568-1
USN-3196-1
USN-3211-1
USN-3211-2

Affected Products

Alt Linux
Php
Suse
Ubuntu