Description
In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.
Remediation
References
Related Vulnerabilities
WordPress Plugin Child Theme Creator by Orbisius Arbitrary File Modification (1.2.6)
WordPress Improper Input Validation Vulnerability (CVE-2017-6815)
MySQL CVE-2024-20981 Vulnerability (CVE-2024-20981)
Moodle Improper Input Validation Vulnerability (CVE-2019-3847)
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3)