PT-2015-3421 · Php+5 · Php+5

Published

2015-04-17

·

Updated

2019-04-22

·

CVE-2015-2783

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.40 PHP versions 5.5.x prior to 5.5.24 PHP versions 5.6.x prior to 5.6.8
Description The issue allows remote attackers to obtain sensitive information from process memory or cause a denial of service, resulting in a buffer over-read and application crash. This is related to the phar parse metadata and phar parse pharfile functions when a crafted length value is used in conjunction with crafted serialized data in a phar archive. The vulnerability can also lead to privilege escalation or disclosure of protected information.
Recommendations For PHP versions prior to 5.4.40, update to version 5.4.40 or later. For PHP versions 5.5.x prior to 5.5.24, update to version 5.5.24 or later. For PHP versions 5.6.x prior to 5.6.8, update to version 5.6.8 or later.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02524
CESA-2015_1135
CESA-2015_1218
CVE-2015-2783
DLA-212-1
DSA-3280-1
HPSBUX03337
MGASA-2015-0169
OPENSUSE-SU-2015_0855-1
RHSA-2015:1066
RHSA-2015:1135
RHSA-2015:1186
RHSA-2015:1187
RHSA-2015:1218
RHSA-2015_1135
RHSA-2015_1218
SUSE-SU-2015:0868-1
SUSE-SU-2016:1638-1
USN-2572-1

Affected Products

Centos
Hp-Ux
Php
Red Hat
Suse
Ubuntu