VYPR
High severity8.8NVD Advisory· Published May 22, 2016· Updated May 6, 2026

CVE-2016-4342

CVE-2016-4342

Description

ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) TAR, (2) ZIP, or (3) PHAR archive.

Affected products

23
  • PHP/PHP22 versions
    cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.5.31
    • cpe:2.3:a:php:php:5.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.17:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.