CVE-2016-10160
php: Off-by-one error in phar_parse_pharfile when loading crafted phar archive
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
Error por un paso en la función phar_parse_pharfile en ext/phar/phar.c en PHP en versiones anteriores a 5.6.30 y 7.0.x en versiones anteriores a 7.0.15 permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) o posiblemente ejecutar código arbitrario a través de un archivo PHAR manipulado con un desajuste del alias.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-01-24 CVE Reserved
- 2017-01-24 CVE Published
- 2024-04-26 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-193: Off-by-one Error
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95783 | Third Party Advisory | |
http://www.securitytracker.com/id/1037659 | Broken Link | |
https://security.netapp.com/advisory/ntap-20180112-0001 | Third Party Advisory | |
https://www.tenable.com/security/tns-2017-04 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugs.php.net/bug.php?id=73768 | 2022-07-20 | |
https://github.com/php/php-src/commit/b28b8b2fee6dfa6fcd13305c581bb835689ac3be | 2022-07-20 |
URL | Date | SRC |
---|---|---|
http://php.net/ChangeLog-5.php | 2022-07-20 | |
http://php.net/ChangeLog-7.php | 2022-07-20 | |
http://www.debian.org/security/2017/dsa-3783 | 2022-07-20 | |
https://access.redhat.com/errata/RHSA-2018:1296 | 2022-07-20 | |
https://security.gentoo.org/glsa/201702-29 | 2022-07-20 | |
https://access.redhat.com/security/cve/CVE-2016-10160 | 2018-05-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1419018 | 2018-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 5.6.0 < 5.6.30 Search vendor "Php" for product "Php" and version " >= 5.6.0 < 5.6.30" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 7.0.0 < 7.0.15 Search vendor "Php" for product "Php" and version " >= 7.0.0 < 7.0.15" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 7.1.0 < 7.1.1 Search vendor "Php" for product "Php" and version " >= 7.1.0 < 7.1.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Clustered Data Ontap Search vendor "Netapp" for product "Clustered Data Ontap" | - | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|