CVE-2015-3329
HIGH severity · CVSS 7.5 · Memory corruption
7.5CVSS HIGH
Summary
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)29%
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products we track (2)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: http://php.net/ChangeLog-5.php ↗
Additional information
- NVD record
- http://php.net/ChangeLog-5.phpPatch
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlAdvisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlAdvisory
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=f59b67ae50064560d7bfcdb0d6a8ab284179053c
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.html
- http://rhn.redhat.com/errata/RHSA-2015-1066.html
- http://rhn.redhat.com/errata/RHSA-2015-1135.htmlAdvisory