9.8
CVSSv3

CVE-2015-5589

Published: 16/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The phar_convert_to_other function in ext/phar/phar_object.c in PHP prior to 5.4.43, 5.5.x prior to 5.5.27, and 5.6.x prior to 5.6.11 does not validate a file pointer before a close operation, which allows remote malicious users to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted TAR archive that is mishandled in a Phar::convertToData call.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.6.1

php php 5.6.0

php php 5.6.5

php php 5.6.4

php php 5.6.6

php php 5.6.2

php php 5.6.10

php php 5.6.7

php php 5.6.9

php php 5.6.3

php php 5.6.8

php php 5.5.0

php php 5.5.19

php php 5.5.25

php php 5.5.16

php php 5.5.1

php php 5.5.5

php php 5.5.21

php php 5.5.17

php php 5.5.14

php php 5.5.7

php php 5.5.12

php php 5.5.6

php php 5.5.3

php php 5.5.23

php php 5.5.8

php php 5.5.24

php php 5.5.15

php php 5.5.11

php php 5.5.13

php php 5.5.4

php php 5.5.26

php php 5.5.10

php php 5.5.22

php php 5.5.18

php php 5.5.20

php php 5.5.2

php php 5.5.9

php php

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in the PHP language: CVE-2015-4598 thoger at redhat dot com discovered that paths containing a NUL character were improperly handled, thus allowing an attacker to manipulate unexpected files on the server CVE-2015-4643 Max Spelsberg discovered an integer overflow flaw leading to a ...
A flaw was found in the way the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...