CVE-2018-20783
published 2019-02-21CVE-2018-20783: In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.66%
92.1th percentile
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
| php | php | < 5.6.40 | 5.6.40 |
| php | php | < 5.6.39 | 5.6.39 |
| php | php | >= 7.0.0 < 7.1.26 | 7.1.26 |
| php | php | >= 7.0.0 < 7.0.33 | 7.0.33 |
| php | php | >= 7.1.0 < 7.1.25 | 7.1.25 |
| php | php | >= 7.2.0 < 7.2.14 | 7.2.14 |
| php | php | >= 7.2.0 < 7.2.13 | 7.2.13 |
| php | php | >= 7.3.0 < 7.3.1 | 7.3.1 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.27 | 5.5.9+dfsg-1ubuntu4.27 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx4f-r59p-mgpx: In PHP before 5
ghsa_unreviewed·2022-05-14
CVE-2018-20783 [HIGH] CWE-125 GHSA-gx4f-r59p-mgpx: In PHP before 5
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
GHSA
GHSA-3fr9-q295-2jq3: An issue was discovered in PHP before 5
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2019-9021 [HIGH] CWE-125 GHSA-3fr9-q295-2jq3: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.
OSV
php5 vulnerabilities
osv·2019-05-22·CVSS 7.5
CVE-2018-20783 [HIGH] php5 vulnerabilities
php5 vulnerabilities
USN-3566-1 fixed several vulnerabilities in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information.
(CVE-2018-20783)
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information or possibly
cause a crash, resulting in a denial of service. (CVE-2019-11036)
Original advisory details:
It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affect
OSV
CVE-2019-9021: An issue was discovered in PHP before 5
osv·2019-02-22·CVSS 7.5
CVE-2019-9021 [HIGH] CVE-2019-9021: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.
OSV
CVE-2018-20783: In PHP before 5
osv·2019-02-21·CVSS 7.5
CVE-2018-20783 [HIGH] CVE-2018-20783: In PHP before 5
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2019-05-22·CVSS 7.5
CVE-2016-10712 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
USN-3566-1 fixed several vulnerabilities in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information.
(CVE-2018-20783)
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information or possibly
cause a crash, resulting in a denial of service. (CVE-2019-11036)
Original advisory details:
It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service,
Red Hat
php: Heap-based buffer over-read in PHAR reading functions
vendor_redhat·2018-12-06·CVSS 7.5
CVE-2019-9021 [HIGH] CWE-122 php: Heap-based buffer over-read in PHAR reading functions
php: Heap-based buffer over-read in PHAR reading functions
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.
Package: php (Red Hat Enterprise Linux 5) - Out of support scope
Package: php (Red Hat Enterprise Linux 6) - Out of support scope
Package: php (Red Hat Enterprise Linux 7) - Fix deferred
Package: rh-php70-php (Red Hat Software Collections) - Fix deferred
Red Hat
php: Buffer over-read in PHAR reading functions
vendor_redhat·2018-11-12·CVSS 7.5
CVE-2018-20783 [HIGH] php: Buffer over-read in PHAR reading functions
php: Buffer over-read in PHAR reading functions
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
Package: php (Red Hat Enterprise Linux 5) - Out of support scope
Package: php (Red Hat Enterprise Linux 6) - Out of support scope
Package: php (Red Hat Enterprise Linux 7) - Fix deferred
Package: rh-php70-php (Red Hat Software Collections) - Fix deferred
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9021 php: Heap-based buffer over-read in PHAR reading functions
bugzilla·2019-03-04·CVSS 7.5
CVE-2019-9021 [HIGH] CVE-2019-9021 php: Heap-based buffer over-read in PHAR reading functions
CVE-2019-9021 php: Heap-based buffer over-read in PHAR reading functions
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.
References:
https://bugs.php.net/bug.php?id=77247
Upstrean commit:
http://git.php.net/?p=php-src.git;a=commit;h=428d8164ffcf6f75a6cc9d4056e54bfd450dac03
http://git.php.net/?p=php-src.git;a=commit;h=78bd3477745f1ada9578a79f61edb41886bec1cb
http://git.php.net/?p=php-src.git;a=commit;h=9d388b95c54ea053ce6f
Bugzilla
CVE-2018-20783 php: Buffer over-read in PHAR reading functions
bugzilla·2019-02-25·CVSS 7.5
CVE-2018-20783 [HIGH] CVE-2018-20783 php: Buffer over-read in PHAR reading functions
CVE-2018-20783 php: Buffer over-read in PHAR reading functions
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
Reference:
https://bugs.php.net/bug.php?id=77143
Discussion:
Upstream commit:
http://git.php.net/?p=php-src.git;a=commitdiff;h=e7c8e6cde021afd637ea535b0641a1851e57fb2a
---
Analysis:
Essentially an OOB read in the PHAR code, which can be triggered by malicious PHAR files. Obviously the php script needs to allow users (attackers) to upload arbitrary PHAR files and they need to be processed via Phar() function. Impact i
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.htmlhttp://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttps://access.redhat.com/errata/RHSA-2019:2519https://access.redhat.com/errata/RHSA-2019:3299https://bugs.php.net/bug.php?id=77143https://usn.ubuntu.com/3566-2/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.htmlhttp://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttps://access.redhat.com/errata/RHSA-2019:2519https://access.redhat.com/errata/RHSA-2019:3299https://bugs.php.net/bug.php?id=77143https://usn.ubuntu.com/3566-2/
2019-02-21
Published