Description
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
Remediation
References
Related Vulnerabilities
Magento Improper Authorization Vulnerability (CVE-2021-28563)
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5475)
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.1)
Java Unspesificed Vulnerability (CVE-2018-2940)
WordPress Plugin Ceceppa Multilingua Cross-Site Scripting (1.5.17)