7.5
CVSSv2

CVE-2015-4026

Published: 09/06/2015 Updated: 22/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The pcntl_exec implementation in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote malicious users to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 6.0

redhat enterprise linux 7.0

php php 5.5.0

php php

php php 5.4.39

php php 5.5.11

php php 5.5.12

php php 5.5.21

php php 5.5.22

php php 5.5.8

php php 5.6.0

php php 5.6.8

php php 5.5.9

php php 5.5.18

php php 5.5.19

php php 5.5.4

php php 5.5.5

php php 5.6.4

php php 5.6.5

php php 5.5.1

php php 5.5.10

php php 5.5.2

php php 5.5.20

php php 5.5.6

php php 5.5.7

php php 5.6.6

php php 5.6.7

php php 5.5.13

php php 5.5.14

php php 5.5.23

php php 5.5.24

php php 5.5.3

php php 5.6.2

php php 5.6.3

apple mac os x

redhat enterprise linux hpc node 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server eus 7.1

redhat enterprise linux hpc node eus 7.1

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names CVE-2015-4024 Denial of service when processing multipart/form-data requests CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentiall ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...
An integer underflow flaw leading to out-of-bounds memory access was found in the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened (CVE-2015-4021) An integer overflow flaw leading to a heap based buffer overflow was found in the way PHP's FTP extens ...