7.5
CVSSv2

CVE-2015-3329

Published: 09/06/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP prior to 5.4.40, 5.5.x prior to 5.5.24, and 5.6.x prior to 5.6.8 allow remote malicious users to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.10.0

apple mac os x

apple mac os x 10.10.4

apple mac os x 10.10.1

apple mac os x 10.9.5

apple mac os x 10.10.3

apple mac os x 10.10.2

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux hpc node 7.0

redhat enterprise linux server eus 7.1

redhat enterprise linux hpc node eus 7.1

oracle solaris 11.2

oracle linux 6

oracle linux 7

php php 5.5.0

php php 5.6.0

php php 5.6.5

php php

php php 5.5.19

php php 5.5.1

php php 5.5.5

php php 5.6.4

php php 5.5.21

php php 5.6.6

php php 5.5.14

php php 5.5.7

php php 5.6.2

php php 5.5.12

php php 5.5.6

php php 5.6.7

php php 5.5.3

php php 5.5.23

php php 5.5.8

php php 5.5.11

php php 5.5.13

php php 5.5.4

php php 5.5.10

php php 5.6.3

php php 5.5.22

php php 5.5.18

php php 5.5.20

php php 5.5.2

php php 5.5.9

redhat enterprise linux 7.0

redhat enterprise linux 6.0

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names CVE-2015-4024 Denial of service when processing multipart/form-data requests CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentiall ...
A buffer overflow flaw was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened ...
A use-after-free flaw was found in PHP's OPcache extension This flaw could possibly lead to a disclosure of portion of server memory (CVE-2015-1351) A NULL pointer dereference flaw was found in PHP's pgsql extension A specially crafted table name passed to function as pg_insert() or pg_select() could cause a PHP application to crash (CVE-2015-1 ...
A use-after-free flaw was found in PHP's OPcache extension This flaw could possibly lead to a disclosure of portion of server memory (CVE-2015-1351) A NULL pointer dereference flaw was found in PHP's pgsql extension A specially crafted table name passed to function as pg_insert() or pg_select() could cause a PHP application to crash (CVE-2015-1 ...
A buffer overflow vulnerability was found in PHP's phar (PHP Archive) implementation See <a href="bugsphpnet/bugphp?id=69324">bugsphpnet/bugphp?id=69324</a> for more details (CVE-2015-2783) A use-after-free flaw was found in PHP's phar (PHP Archive) paths implementation A malicious script author could possibly ...