Description
The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted TAR archive that is mishandled in a Phar::convertToData call.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Google Fonts Cross-Site Scripting (3.1.3)
Apache Tomcat Insertion of Sensitive Information into Log File Vulnerability (CVE-2026-34487)
WordPress Plugin The Plus Addons for Elementor Open Redirect (4.1.9)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-7491)
SugarCRM Missing Authorization Vulnerability (CVE-2020-7472)