RULE(RULE ID:317509)

Rule General Information
Release Date: 2017-06-02
Rule Name: PHP Phar_parse_pharfile Function Filename_len Property Integer Overflow Vulnerability (CVE-2016-10159)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive.
Impact: An attacker can exploit the affected software with an integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:95774
SecurityTrackerID:1037659
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://php.net/ChangeLog-7.php
http://php.net/ChangeLog-5.php