4.3
CVE-2026-6103
- EPSS 0.17%
- Veröffentlicht 25.09.2026 20:08:49
- Zuletzt bearbeitet 29.09.2026 21:27:41
- Erkennungen
Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Group
≫
Produkt
PHP
Default Statusunaffected
Version
8.2.*
Version <
8.2.34
Status
affected
Version
8.3.*
Version <
8.3.35
Status
affected
Version
8.4.*
Version <
8.4.26
Status
affected
Version
8.5.*
Version <
8.5.11
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| PHP | 4.3 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-190 Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85