CVE-2016-4473: PHP
Critical severity, CVSS 9.8. EPSS: 7.8% chance of exploitation in the next 30 days.
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
Affected products
- PHP PHP: version 5.6.0 only; version 5.6.1 only; version 5.6.2 only; version 5.6.3 only; version 5.6.4 only; version 5.6.5 only; …
- Suse Linux Enterprise Module For Web Scripting: version 12 only
- Suse Linux Enterprise Software Development Kit: version 12 only
Published 2017-06-08. Last modified 2026-06-17.