In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
| Software | From | Fixed in |
|---|---|---|
| php / php | 7.2.0 | 7.2.27.x |
| php / php | 7.3.0 | 7.3.14.x |
| php / php | 7.4.0 | 7.4.2.x |
| tenable / tenable.sc | - | 5.19.0 |