CVE-2020-7061: php: heap-based buffer overflow in phar_extract_file

Severity: Critical

CVSS Score: 9.1

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.