Description
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
Remediation
References
Related Vulnerabilities
Nginx Improper Certificate Validation Vulnerability (CVE-2021-3618)
WordPress Plugin Events Made Easy SQL Injection (2.2.35)
Magento Improper Authentication Vulnerability (CVE-2015-3457)
PHP Other Vulnerability (CVE-2005-3391)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3558)