5
CVSSv2

CVE-2015-4021

Published: 09/06/2015 Updated: 22/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The phar_parse_tarfile function in ext/phar/tar.c in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote malicious users to cause a denial of service (integer underflow and memory corruption) via a crafted entry in a tar archive.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux hpc node eus 7.1

redhat enterprise linux workstation 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server eus 7.1

redhat enterprise linux server 7.0

redhat enterprise linux hpc node 7.0

apple mac os x

redhat enterprise linux 7.0

redhat enterprise linux 6.0

php php 5.5.0

php php 5.5.1

php php 5.5.19

php php 5.5.2

php php 5.5.4

php php 5.5.5

php php 5.6.0

php php 5.6.5

php php 5.6.6

php php 5.4.39

php php 5.5.12

php php 5.5.13

php php 5.5.22

php php 5.5.23

php php 5.5.8

php php 5.6.2

php php 5.5.9

php php 5.5.14

php php 5.5.18

php php 5.5.24

php php 5.5.3

php php 5.6.3

php php 5.6.4

php php

php php 5.5.10

php php 5.5.11

php php 5.5.20

php php 5.5.21

php php 5.5.6

php php 5.5.7

php php 5.6.7

php php 5.6.8

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names CVE-2015-4024 Denial of service when processing multipart/form-data requests CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentiall ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...