7.5
CVSSv2

CVE-2015-3307

Published: 09/06/2015 Updated: 22/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The phar_parse_metadata function in ext/phar/phar.c in PHP prior to 5.4.40, 5.5.x prior to 5.5.24, and 5.6.x prior to 5.6.8 allows remote malicious users to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux server eus 7.1

redhat enterprise linux hpc node eus 7.1

redhat enterprise linux hpc node 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux 6.0

redhat enterprise linux 7.0

apple mac os x

php php 5.5.0

php php 5.5.1

php php 5.5.19

php php 5.5.2

php php 5.5.20

php php 5.5.6

php php 5.5.7

php php 5.6.0

php php 5.6.6

php php 5.6.7

php php 5.5.9

php php 5.5.14

php php 5.5.18

php php 5.5.4

php php 5.5.5

php php 5.6.4

php php 5.6.5

php php 5.5.12

php php 5.5.13

php php 5.5.23

php php 5.5.3

php php 5.6.2

php php 5.6.3

php php

php php 5.5.10

php php 5.5.11

php php 5.5.21

php php 5.5.22

php php 5.5.8