CVE-2016-10159: Debian Linux
High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.
Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive.
Affected products
- Debian Debian Linux: version 8.0 only
- PHP PHP: up to and including 5.6.29; from 7.0.0, before 7.0.15 (fixed in 7.0.15); version 7.1.0 only
Published 2017-01-24. Last modified 2026-06-17.