CVE-2016-4072
20.05.2016, 11:00
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.Enginsight
| Vendor | Product | Version |
|---|---|---|
| php | php | 5.6.0:alpha1 |
| php | php | 5.6.0:alpha2 |
| php | php | 5.6.0:alpha3 |
| php | php | 5.6.0:alpha4 |
| php | php | 5.6.0:alpha5 |
| php | php | 5.6.0:beta1 |
| php | php | 5.6.0:beta2 |
| php | php | 5.6.0:beta3 |
| php | php | 5.6.0:beta4 |
| php | php | 5.6.1 |
| php | php | 5.6.2 |
| php | php | 5.6.3 |
| php | php | 5.6.4 |
| php | php | 5.6.5 |
| php | php | 5.6.6 |
| php | php | 5.6.7 |
| php | php | 5.6.8 |
| php | php | 5.6.9 |
| php | php | 5.6.10 |
| php | php | 5.6.11 |
| php | php | 5.6.12 |
| php | php | 5.6.13 |
| php | php | 5.6.14 |
| php | php | 5.6.15 |
| php | php | 5.6.16 |
| php | php | 5.6.17 |
| php | php | 5.6.18 |
| php | php | 5.6.19 |
| php | php | 7.0.0 |
| php | php | 7.0.1 |
| php | php | 7.0.2 |
| php | php | 7.0.3 |
| php | php | 7.0.4 |
| apple | mac_os_x | 𝑥 ≤ 10.11.4 |
| php | php | 5.5.0 |
| php | php | 5.5.0:alpha1 |
| php | php | 5.5.0:alpha2 |
| php | php | 5.5.0:alpha3 |
| php | php | 5.5.0:alpha4 |
| php | php | 5.5.0:alpha5 |
| php | php | 5.5.0:alpha6 |
| php | php | 5.5.0:beta1 |
| php | php | 5.5.0:beta2 |
| php | php | 5.5.0:beta3 |
| php | php | 5.5.0:beta4 |
| php | php | 5.5.0:rc1 |
| php | php | 5.5.0:rc2 |
| php | php | 5.5.1 |
| php | php | 5.5.2 |
| php | php | 5.5.3 |
| php | php | 5.5.4 |
| php | php | 5.5.5 |
| php | php | 5.5.6 |
| php | php | 5.5.7 |
| php | php | 5.5.8 |
| php | php | 5.5.9 |
| php | php | 5.5.10 |
| php | php | 5.5.11 |
| php | php | 5.5.12 |
| php | php | 5.5.13 |
| php | php | 5.5.14 |
| php | php | 5.5.15 |
| php | php | 5.5.16 |
| php | php | 5.5.17 |
| php | php | 5.5.18 |
| php | php | 5.5.19 |
| php | php | 5.5.20 |
| php | php | 5.5.21 |
| php | php | 5.5.22 |
| php | php | 5.5.23 |
| php | php | 5.5.24 |
| php | php | 5.5.25 |
| php | php | 5.5.26 |
| php | php | 5.5.27 |
| php | php | 5.5.29 |
| php | php | 5.5.30 |
| php | php | 5.5.31 |
| php | php | 5.5.32 |
| php | php | 5.5.33 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References