SynopsisThe version of PHP running on the remote web server is affected by a use-after-free vulnerability.
DescriptionAccording to its self-reported version number, the version of PHP running on the remote web server is 7.2.x prior to 7.2.33. It is, therefore affected by a use-after-free vulnerability in the phar_parse function due to mishandling of the actual_alias variable. An unauthenticated, remote attacker could exploit this issue by dereferencing a freed pointer which could lead to arbitrary code execution.
SolutionUpgrade to PHP version 7.2.33