Security Advisory

CVE-2015-3307

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2015-06-09 18:00:00
Last updated 2024-08-06 05:39:32
Assigner mitre
State PUBLISHED

Description

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.