Back

HIGH

php: buffer overflow in ext/phar/tar.c

Published Mar 11, 2019

Description

An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible.

Affected products

Remediation

Red Hat statement

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 11, 2019
Updated Aug 4, 2024
Reserved Mar 11, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Feb 8, 2019