CVE-2015-1352NULL Pointer Dereference in PHP

Severity
7.5HIGHNVD
NVD5.0OSV5.0
EPSS
30.9%
top 3.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMay 14

Description

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDphp/php5.5.05.5.24+39
Ubuntuphp5/php5< 5.5.9+dfsg-1ubuntu4.11+1
NVDapple/mac_os_x10.10.5

Also affects: Enterprise Linux 6.0, 7.0

🔴Vulnerability Details

5
GHSA
GHSA-xhh6-8vwc-47w8: The php_pgsql_meta_data function in pgsql2022-05-14
GHSA
GHSA-j4qg-8m5f-3hcv: The build_tablename function in pgsql2022-05-13
OSV
CVE-2015-4644: The php_pgsql_meta_data function in pgsql2015-06-18
OSV
php5 vulnerabilities2015-02-17
OSV
CVE-2015-1352: The build_tablename function in pgsql2015-01-26

📋Vendor Advisories

4
Red Hat
php: NULL pointer dereference in php_pgsql_meta_data()2015-06-11
Ubuntu
PHP vulnerabilities2015-02-17
Red Hat
php: NULL pointer dereference in pgsql extension2015-01-04
Apple
CVE-2015-1352: OS X El Capitan v10.11

💬Community

3
Bugzilla
CVE-2015-4644 php: NULL pointer dereference in php_pgsql_meta_data()2015-06-23
Bugzilla
CVE-2015-1351 CVE-2015-1352 CVE-2015-1353 php: various flaws [fedora-all]2015-01-26
Bugzilla
CVE-2015-1352 php: NULL pointer dereference in pgsql extension2015-01-26
CVE-2015-1352 — NULL Pointer Dereference in PHP | cvebase