High severity8.8NVD Advisory· Published May 22, 2016· Updated Jun 17, 2026
CVE-2016-4343
CVE-2016-4343
Description
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
10- bugs.php.net/bug.phpnvdExploitIssue TrackingVendor Advisory
- lists.opensuse.org/opensuse-updates/2016-05/msg00086.htmlnvdMailing ListThird Party Advisory
- php.net/ChangeLog-5.phpnvdRelease NotesVendor Advisory
- php.net/ChangeLog-7.phpnvdRelease NotesVendor Advisory
- rhn.redhat.com/errata/RHSA-2016-2750.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/04/28/2nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/89179nvdThird Party AdvisoryVDB Entry
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
News mentions
0No linked articles in our index yet.