Lucene search

K
f5F5F5:K08206127
HistoryJun 21, 2016 - 12:00 a.m.

K08206127 : PHP vulnerability CVE-2016-4072

2016-06-2100:00:00
my.f5.com
93

AI Score

7.7

Confidence

Low

EPSS

0.069

Percentile

93.9%

Security Advisory Description

The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c. (CVE-2016-4072)
Impact
There is no impact; F5 products are not affected by this vulnerability.