Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP phar扩展phar_object.c多个格式化字符串漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP 5.3.5及之前版本的phar扩展中的phar_object.c中存在多个格式化字符串漏洞。上下文攻击者可以借助向某个类函数传递的参数中的字符串标识符,从进程内存中获取敏感信息,导致拒绝服务(内存破坏),或者可能执行任意代码。该漏洞导致zend_throw_exception_ex的不
CVSS Information
N/A
Vulnerability Type
N/A