CVE-2015-4025
published 2015-06-09CVE-2015-4025: PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows…
PriorityP351high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
20.23%
97.2th percentile
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| php | php | <= 5.4.40 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8472-42qg-pj78: PHP before 5
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2015-4025 [MEDIUM] GHSA-8472-42qg-pj78: PHP before 5
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
OSV
php5 vulnerabilities
osv·2015-07-06·CVSS 6.5
CVE-2015-3411 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Neal Poole and Tomas Hoger discovered that PHP incorrectly handled NULL
bytes in file paths. A remote attacker could possibly use this issue to
bypass intended restrictions and create or obtain access to sensitive
files. (CVE-2015-3411, CVE-2015-3412, CVE-2015-4025, CVE-2015-4026,
CVE-2015-4598)
Emmanuel Law discovered that the PHP phar extension incorrectly handled
filenames starting with a NULL byte. A remote attacker could use this issue
with a crafted tar archive to cause a denial of service. (CVE-2015-4021)
Max Spelsberg discovered that PHP incorrectly handled the LIST command
when connecting to remote FTP servers. A malicious FTP server could
possibly use this issue to execute arbitrary code. (CVE-2015-4022,
CVE-2015-4643)
Shusheng Liu discovered that PHP inc
OSV
CVE-2015-4025: PHP before 5
osv·2015-06-09·CVSS 5.0
CVE-2015-4025 [MEDIUM] CVE-2015-4025: PHP before 5
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-07-06·CVSS 6.5
CVE-2015-3411 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Neal Poole and Tomas Hoger discovered that PHP incorrectly handled NULL
bytes in file paths. A remote attacker could possibly use this issue to
bypass intended restrictions and create or obtain access to sensitive
files. (CVE-2015-3411, CVE-2015-3412, CVE-2015-4025, CVE-2015-4026,
CVE-2015-4598)
Emmanuel Law discovered that the PHP phar extension incorrectly handled
filenames starting with a NULL byte. A remote attacker could use this issue
with a crafted tar archive to cause a denial of service. (CVE-2015-4021)
Max Spelsberg discovered that PHP incorrectly handled the LIST command
when connecting to remote FTP servers. A malicious FTP server could
possibly use this issue to execute arbitrary code. (CVE-2015
Red Hat
php: regressions in 5.4+
vendor_redhat·2015-04-10·CVSS 5.0
CVE-2015-4025 [MEDIUM] CWE-626 php: regressions in 5.4+
php: regressions in 5.4+
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
It was found that certain PHP functions did not properly handle file names containing a NULL character. A remote attacker could possibly use this flaw to make a PHP script access unexpected files and bypass intended file system access restrictions.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Ente
Apple
CVE-2015-4025: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 7.5
CVE-2015-4025 [HIGH] CVE-2015-4025: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-4025
Component: CVE-2015-4025
No detection rules found.
No public exploits indexed.
Tenable
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
blogs_tenable·2015-06-15
[R4] SecurityCenter 5.0.0.1 Affected by Third-party Library
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-4021 CVE-2015-4025 CVE-2015-4026 php: various flaws [fedora-all]
bugzilla·2015-05-20·CVSS 5.0
CVE-2015-4021 [MEDIUM] CVE-2015-4021 CVE-2015-4025 CVE-2015-4026 php: various flaws [fedora-all]
CVE-2015-4021 CVE-2015-4025 CVE-2015-4026 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2015-4026 php: pcntl_exec() accepts paths with NUL character
bugzilla·2015-05-20·CVSS 5.0
CVE-2015-4026 [MEDIUM] CVE-2015-4026 php: pcntl_exec() accepts paths with NUL character
CVE-2015-4026 php: pcntl_exec() accepts paths with NUL character
It was reported that pcntl_exec() function does not check path validity, which may lead to information disclosure, or denial of service attack under certain circumstances.
Upstream report:
https://bugs.php.net/bug.php?id=68598
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=be9b2a95adb504abd5acdc092d770444ad6f6854
CVE request:
http://seclists.org/oss-sec/2015/q2/479
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1223447]
---
php-5.6.9-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
This is another CVE-2006-7243 (see bug 662707) like issue. Fixed as part of the commit that addressed CVE
Bugzilla
CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
bugzilla·2015-05-20·CVSS 5.0
CVE-2015-4025 [MEDIUM] CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
CVE-2015-4025 php: CVE-2006-7243 regressions in 5.4+
Regressions of parts of the CVE-2006-7243 fix were found in PHP >= 5.4. This issue is similar to CVE-2015-2348 (bug 1207682) and CVE-2014-5120 (bug 1132793).
Upstream report:
https://bugs.php.net/bug.php?id=69418
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=be9b2a95adb504abd5acdc092d770444ad6f6854
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1223447]
---
I noted CVE-2006-7243 (see bug 662707) regressions in PHP 5.4+ for the following functions in the upstream bug report:
- set_include_path()
- tempnam() - second argument only
- rmdir()
- readlink()
readlink() was already fixed in 5.4.40 / 5.5.24 / 5.6.8, see bug 1213407 comment 5.
Linked upstream commit includes additional fi
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158616.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158915.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/159031.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1186.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1187.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1219.htmlhttp://www.debian.org/security/2015/dsa-3280http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/74904http://www.securitytracker.com/id/1032431https://bugs.php.net/bug.php?id=69418https://security.gentoo.org/glsa/201606-10https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158616.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158915.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/159031.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1186.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1187.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1219.htmlhttp://www.debian.org/security/2015/dsa-3280http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/74904http://www.securitytracker.com/id/1032431https://bugs.php.net/bug.php?id=69418https://security.gentoo.org/glsa/201606-10https://support.apple.com/kb/HT205031
2015-06-09
Published