CVE-2015-4021 — Integer Overflow or Wraparound in Apple MAC OS X
Severity
5.0MEDIUMNVD
EPSS
42.0%
top 2.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateMay 14
Description
The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a denial of service (integer underflow and memory corruption) via a crafted entry in a tar archive.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages7 packages
Also affects: Enterprise Linux 6.0, 7.0, 7.1