7.5
CVSSv2

CVE-2015-4025

Published: 09/06/2015 Updated: 22/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote malicious users to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

php php 5.5.0

php php 5.5.14

php php 5.5.18

php php 5.5.24

php php 5.5.3

php php 5.6.0

php php 5.6.3

php php 5.6.4

php php

php php 5.5.10

php php 5.5.11

php php 5.5.20

php php 5.5.21

php php 5.5.6

php php 5.5.7

php php 5.5.8

php php 5.6.7

php php 5.6.8

php php 5.4.39

php php 5.5.12

php php 5.5.13

php php 5.5.22

php php 5.5.23

php php 5.6.2

php php 5.5.9

php php 5.5.1

php php 5.5.19

php php 5.5.2

php php 5.5.4

php php 5.5.5

php php 5.6.5

php php 5.6.6

redhat enterprise linux server eus 7.1

redhat enterprise linux hpc node eus 7.1

redhat enterprise linux hpc node 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux 7.0

redhat enterprise linux 6.0

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names CVE-2015-4024 Denial of service when processing multipart/form-data requests CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentiall ...
It was found that certain PHP functions did not properly handle file names containing a NULL character A remote attacker could possibly use this flaw to make a PHP script access unexpected files and bypass intended file system access restrictions ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
SecurityCenter is potentially impacted by several vulnerabilities in PHP that were recently disclosed and fixed Note that due to the time involved in doing a full analysis of each issue, Tenable has opted to patch the included version of PHP as a precaution, and to save time CVE-2015-4025: PHP Multiple NULL Byte Injection Filter Bypass Weaknesse ...