CVE-2015-4022 — Integer Overflow or Wraparound in Apple MAC OS X
CWE-189CWE-190 — Integer Overflow or WraparoundCWE-122 — Heap-based Buffer Overflow11 documents8 sources
Severity
7.5HIGHNVD
EPSS
20.6%
top 4.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateMay 14
Description
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages7 packages
Also affects: Enterprise Linux 6.0, 7.0, 7.1
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4Red Hat▶
php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)↗2015-06-11