High severity8.8NVD Advisory· Published May 22, 2016· Updated May 6, 2026
CVE-2016-4343
CVE-2016-4343
Description
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- bugs.php.net/bug.phpnvdExploitIssue TrackingVendor Advisory
- lists.opensuse.org/opensuse-updates/2016-05/msg00086.htmlnvdMailing ListThird Party Advisory
- php.net/ChangeLog-5.phpnvdRelease NotesVendor Advisory
- php.net/ChangeLog-7.phpnvdRelease NotesVendor Advisory
- rhn.redhat.com/errata/RHSA-2016-2750.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/04/28/2nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/89179nvdThird Party AdvisoryVDB Entry
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
News mentions
0No linked articles in our index yet.