In PHP versions prior to 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php php |
||
fedoraproject fedora 35 |
||
fedoraproject fedora 36 |
||
fedoraproject fedora 37 |
||
debian debian linux 10.0 |
||
debian debian linux 11.0 |