Loading HuntDB...

GHSA-q362-2hc9-hr5r

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.

Related CVEs

Key Information

GHSA ID
GHSA-q362-2hc9-hr5r
Published
May 13, 2022 1:38 AM
Last Modified
April 12, 2025 12:46 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 30, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.