CVE-2015-1352
published 2015-03-30CVE-2015-1352: The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.70%
93.9th percentile
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.5 | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| php | php | < 5.4.40 | 5.4.40 |
| php | php | <= 5.4.41 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php: NULL pointer dereference in php_pgsql_meta_data()
vendor_redhat·2015-06-11·CVSS 5.0
CVE-2015-4644 [MEDIUM] CWE-476 php: NULL pointer dereference in php_pgsql_meta_data()
php: NULL pointer dereference in php_pgsql_meta_data()
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not planned to be corrected in future updates for php packages in Red Hat Enterprise Linux 6 and 7, and php53 packages in Red Hat Enterprise Linux 5. The php packages in Red Hat Enterprise Linux 5 were not affected by this is
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-02-17·CVSS 7.5
CVE-2014-8142 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Stefan Esser discovered that PHP incorrectly handled unserializing objects.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2014-8142,
CVE-2015-0231)
Brian Carpenter discovered that the PHP CGI component incorrectly handled
invalid files. A local attacker could use this issue to obtain sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)
It was discovered that PHP incorrectly handled certain pascal strings in
the fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. This
Red Hat
php: NULL pointer dereference in pgsql extension
vendor_redhat·2015-01-04·CVSS 5.0
CVE-2015-1352 [MEDIUM] CWE-476 php: NULL pointer dereference in pgsql extension
php: NULL pointer dereference in pgsql extension
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
A NULL pointer dereference flaw was found in PHP's pgsql extension. A specially crafted table name passed to a function such as pg_insert() or pg_select() could cause a PHP application to crash.
Statement: This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) -
Apple
CVE-2015-1352: OS X El Capitan v10.11
vendor_apple·CVSS 5.0
CVE-2015-1352 [MEDIUM] CVE-2015-1352: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-1352
Component: CVE-2015-1352
GHSA
GHSA-xhh6-8vwc-47w8: The php_pgsql_meta_data function in pgsql
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2015-4644 [MEDIUM] GHSA-xhh6-8vwc-47w8: The php_pgsql_meta_data function in pgsql
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.
GHSA
GHSA-j4qg-8m5f-3hcv: The build_tablename function in pgsql
ghsa_unreviewed·2022-05-13
CVE-2015-1352 [MEDIUM] GHSA-j4qg-8m5f-3hcv: The build_tablename function in pgsql
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
OSV
CVE-2015-4644: The php_pgsql_meta_data function in pgsql
osv·2015-06-18·CVSS 5.0
CVE-2015-4644 [MEDIUM] CVE-2015-4644: The php_pgsql_meta_data function in pgsql
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.
OSV
php5 vulnerabilities
osv·2015-02-17·CVSS 7.5
CVE-2014-8142 [HIGH] php5 vulnerabilities
php5 vulnerabilities
Stefan Esser discovered that PHP incorrectly handled unserializing objects.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2014-8142,
CVE-2015-0231)
Brian Carpenter discovered that the PHP CGI component incorrectly handled
invalid files. A local attacker could use this issue to obtain sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)
It was discovered that PHP incorrectly handled certain pascal strings in
the fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CV
OSV
CVE-2015-1352: The build_tablename function in pgsql
osv·2015-01-26·CVSS 5.0
CVE-2015-1352 [MEDIUM] CVE-2015-1352: The build_tablename function in pgsql
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4644 php: NULL pointer dereference in php_pgsql_meta_data()
bugzilla·2015-06-23·CVSS 5.0
CVE-2015-4644 [MEDIUM] CVE-2015-4644 php: NULL pointer dereference in php_pgsql_meta_data()
CVE-2015-4644 php: NULL pointer dereference in php_pgsql_meta_data()
PHP versions 5.4.42, 5.5.26, and 5.6.10 provide a fix for segmentation fault in php_pgsql_meta_data():
Fixed bug #69667 (segfault in php_pgsql_meta_data).
Upstream bug:
https://bugs.php.net/bug.php?id=69667
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=2cc4e69cc6d8dbc4b3568ad3dd583324a7c11d64
Not security bug upstream, but we found this when testing updates with fixes for CVE-2015-1352 (see bug 1185904).
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1234942]
---
Unlike the CVE-2015-1352 issue, this also affected older PHP versions including PHP 5.3.3 as shipped with Red Hat Enterprise Linux.
This issue was already corrected in latest Red Hat Software Collections
Bugzilla
CVE-2015-1351 CVE-2015-1352 CVE-2015-1353 php: various flaws [fedora-all]
bugzilla·2015-01-26·CVSS 7.5
CVE-2015-1351 [HIGH] CVE-2015-1351 CVE-2015-1352 CVE-2015-1353 php: various flaws [fedora-all]
CVE-2015-1351 CVE-2015-1352 CVE-2015-1353 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2015-1352 php: NULL pointer dereference in pgsql extension
bugzilla·2015-01-26·CVSS 5.0
CVE-2015-1352 [MEDIUM] CVE-2015-1352 php: NULL pointer dereference in pgsql extension
CVE-2015-1352 php: NULL pointer dereference in pgsql extension
It was reported [1] that a null pointer dereference is possible in 'pgsql' PHP extension, when running pg_insert() with a NULL table-name.
Upstream commit with the fix:
http://git.php.net/?p=php-src.git;a=commit;h=124fb22a13fafa3648e4e15b4f207c7096d8155e
[1]: https://bugs.php.net/bug.php?id=68741
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1185897]
---
Notice about this issue: If the (remote) user can change the SQL request to send a NULL table-name, the system have much more serious issues that this segfault.
---
This issue was introduced via this bug / commit:
https://bugs.php.net/bug.php?id=62978
http://git.php.net/?p=php-src.git;a=commitdiff;h=f718684a6c1d6221015031d1e72d3eb55ecb
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=124fb22a13fafa3648e4e15b4f207c7096d8155ehttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://marc.info/?l=bugtraq&m=143403519711434&w=2http://openwall.com/lists/oss-security/2015/01/24/9http://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:079http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/71932https://bugs.php.net/bug.php?id=68741https://security.gentoo.org/glsa/201606-10https://support.apple.com/HT205267http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=124fb22a13fafa3648e4e15b4f207c7096d8155ehttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://marc.info/?l=bugtraq&m=143403519711434&w=2http://openwall.com/lists/oss-security/2015/01/24/9http://rhn.redhat.com/errata/RHSA-2015-1053.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:079http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/71932https://bugs.php.net/bug.php?id=68741https://security.gentoo.org/glsa/201606-10https://support.apple.com/HT205267
2015-03-30
Published