CVE-2016-10160

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
References
Link Resource
http://php.net/ChangeLog-5.php Release Notes Vendor Advisory
http://php.net/ChangeLog-7.php Release Notes Vendor Advisory
http://www.debian.org/security/2017/dsa-3783 Third Party Advisory
http://www.securityfocus.com/bid/95783 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037659 Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:1296 Third Party Advisory
https://bugs.php.net/bug.php?id=73768 Issue Tracking Patch Vendor Advisory
https://github.com/php/php-src/commit/b28b8b2fee6dfa6fcd13305c581bb835689ac3be Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/201702-29 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180112-0001/ Third Party Advisory
https://www.tenable.com/security/tns-2017-04 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

20 Jul 2022, 16:58

Type Values Removed Values Added
CPE cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
References (CONFIRM) https://www.tenable.com/security/tns-2017-04 - (CONFIRM) https://www.tenable.com/security/tns-2017-04 - Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20180112-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20180112-0001/ - Third Party Advisory
References (SECTRACK) http://www.securitytracker.com/id/1037659 - (SECTRACK) http://www.securitytracker.com/id/1037659 - Broken Link, Third Party Advisory, VDB Entry
References (GENTOO) https://security.gentoo.org/glsa/201702-29 - (GENTOO) https://security.gentoo.org/glsa/201702-29 - Third Party Advisory
References (DEBIAN) http://www.debian.org/security/2017/dsa-3783 - (DEBIAN) http://www.debian.org/security/2017/dsa-3783 - Third Party Advisory
References (CONFIRM) https://bugs.php.net/bug.php?id=73768 - Issue Tracking (CONFIRM) https://bugs.php.net/bug.php?id=73768 - Issue Tracking, Patch, Vendor Advisory
References (REDHAT) https://access.redhat.com/errata/RHSA-2018:1296 - (REDHAT) https://access.redhat.com/errata/RHSA-2018:1296 - Third Party Advisory
CWE CWE-119 CWE-193

Information

Published : 2017-01-24 21:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-10160

Mitre link : CVE-2016-10160

CVE.ORG link : CVE-2016-10160


JSON object : View

Products Affected

netapp

  • clustered_data_ontap

debian

  • debian_linux

php

  • php
CWE
CWE-193

Off-by-one Error