Description
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
Remediation
References
Related Vulnerabilities
Drupal Core 8.6.x Cross-Site Scripting (8.6.0 - 8.6.12)
WordPress Plugin Custom CSS Pro Cross-Site Request Forgery (1.0.3)
WordPress Plugin CMS Tree Page View Cross-Site Request Forgery (1.2.4)
Joomla CVE-2022-27911 Vulnerability (CVE-2022-27911)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-43950)