Description
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
Remediation
References
Related Vulnerabilities
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.11)
WordPress Plugin Sitemap Cross-Site Scripting (4.3)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-3902)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4279)
WordPress Plugin WP Affiliate Platform Multiple Vulnerabilities (6.3.9)