phar_tar_number() 函数在解析 TAR 头部的八进制大小字段时,将其转换为 uint32_t 类型,但未进行溢出检查。该字段宽度为 11 个八进制位,可表示的最大值为 0x1FFFFFFFF;因此,当实际大小超过 0xFFFFFFFF 时,会发生静默截断(回绕)。解析器随后会错误地跳过相应数量的数据块,并将攻击者控制的文件内容误解释为下一个 TAR 头部。这种漏洞使得恶意构造的归档文件能够注入伪造的条目,导致 PharData 将这些条目报告并提取为合法内容,从而产生安全风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-17545 | 6.9 MEDIUM | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca |
| CVE-2026-91767 | 6.5 MEDIUM | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2025-14181 | 6.5 MEDIUM | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-91766 | 5.9 MEDIUM | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-91769 | 4.3 MEDIUM | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet