PT-2015-3421 · Php+5 · Php+5

Publicado

2015-04-17

·

Atualizado

2019-04-22

·

CVE-2015-2783

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.40 PHP versions 5.5.x prior to 5.5.24 PHP versions 5.6.x prior to 5.6.8
Description The issue allows remote attackers to obtain sensitive information from process memory or cause a denial of service, resulting in a buffer over-read and application crash. This is related to the phar parse metadata and phar parse pharfile functions when a crafted length value is used in conjunction with crafted serialized data in a phar archive. The vulnerability can also lead to privilege escalation or disclosure of protected information.
Recommendations For PHP versions prior to 5.4.40, update to version 5.4.40 or later. For PHP versions 5.5.x prior to 5.5.24, update to version 5.5.24 or later. For PHP versions 5.6.x prior to 5.6.8, update to version 5.6.8 or later.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02524
CESA-2015_1135
CESA-2015_1218
CVE-2015-2783
DLA-212-1
DSA-3280-1
HPSBUX03337
MGASA-2015-0169
OPENSUSE-SU-2015_0855-1
RHSA-2015:1066
RHSA-2015:1135
RHSA-2015:1186
RHSA-2015:1187
RHSA-2015:1218
RHSA-2015_1135
RHSA-2015_1218
SUSE-SU-2015:0868-1
SUSE-SU-2016:1638-1
USN-2572-1

Produtos afetados

Centos
Hp-Ux
Php
Red Hat
Suse
Ubuntu