CVE-2019-9675 PUBLISHED

An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible.

EPSS 0.49% · 65.3th percentile

Risk Scores

EPSS Score
0.49%
65.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSphp7.20, 7.2.15-0ubuntu0.18.04.1, 7.2.10-0ubuntu0.18.04.1
Ubuntu:16.04:LTSphp7.07.0.4-7ubuntu1, 0, 7.0.1-5
Ubuntu:14.04:LTSphp55.5.3+dfsg-1ubuntu3, 5.5.3+dfsg-1ubuntu2, 5.5.9+dfsg-1ubuntu4.1

Timeline

References

Open in Interactive Console →