CVE-2015-4643
published 2016-05-16CVE-2015-4643: Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to…
PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
16.95%
96.7th percentile
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| php | php | < 5.4.42 | 5.4.42 |
| php | php | >= 5.5.0 < 5.5.26 | 5.5.26 |
| php | php | >= 5.6.0 < 5.6.10 | 5.6.10 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.11 | 5.5.9+dfsg-1ubuntu4.11 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phcc-83hq-g329: Integer overflow in the ftp_genlist function in ext/ftp/ftp
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2015-4643 [HIGH] CWE-119 GHSA-phcc-83hq-g329: Integer overflow in the ftp_genlist function in ext/ftp/ftp
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
OSV
php5 vulnerabilities
osv·2015-07-06·CVSS 6.5
CVE-2015-3411 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Neal Poole and Tomas Hoger discovered that PHP incorrectly handled NULL
bytes in file paths. A remote attacker could possibly use this issue to
bypass intended restrictions and create or obtain access to sensitive
files. (CVE-2015-3411, CVE-2015-3412, CVE-2015-4025, CVE-2015-4026,
CVE-2015-4598)
Emmanuel Law discovered that the PHP phar extension incorrectly handled
filenames starting with a NULL byte. A remote attacker could use this issue
with a crafted tar archive to cause a denial of service. (CVE-2015-4021)
Max Spelsberg discovered that PHP incorrectly handled the LIST command
when connecting to remote FTP servers. A malicious FTP server could
possibly use this issue to execute arbitrary code. (CVE-2015-4022,
CVE-2015-4643)
Shusheng Liu discovered that PHP inc
OSV
CVE-2015-4643: Integer overflow in the ftp_genlist function in ext/ftp/ftp
osv·2015-06-18·CVSS 7.5
CVE-2015-4643 [HIGH] CVE-2015-4643: Integer overflow in the ftp_genlist function in ext/ftp/ftp
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-07-06·CVSS 6.5
CVE-2015-3411 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Neal Poole and Tomas Hoger discovered that PHP incorrectly handled NULL
bytes in file paths. A remote attacker could possibly use this issue to
bypass intended restrictions and create or obtain access to sensitive
files. (CVE-2015-3411, CVE-2015-3412, CVE-2015-4025, CVE-2015-4026,
CVE-2015-4598)
Emmanuel Law discovered that the PHP phar extension incorrectly handled
filenames starting with a NULL byte. A remote attacker could use this issue
with a crafted tar archive to cause a denial of service. (CVE-2015-4021)
Max Spelsberg discovered that PHP incorrectly handled the LIST command
when connecting to remote FTP servers. A malicious FTP server could
possibly use this issue to execute arbitrary code. (CVE-2015
Red Hat
php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
vendor_redhat·2015-06-11·CVSS 7.5
CVE-2015-4643 [HIGH] CWE-190 php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4644 CVE-2015-4643 php: various flaws [fedora-all]
bugzilla·2015-06-23·CVSS 9.8
CVE-2015-4644 [CRITICAL] CVE-2015-4644 CVE-2015-4643 php: various flaws [fedora-all]
CVE-2015-4644 CVE-2015-4643 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2015-4643 php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
bugzilla·2015-06-23·CVSS 7.5
CVE-2015-4643 [HIGH] CVE-2015-4643 php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
CVE-2015-4643 php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)
PHP versions 5.4.42, 5.5.26, and 5.6.10 provide improved fix for CVE-2015-4022:
Improved fix for bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow).
Upstream bug:
https://bugs.php.net/bug.php?id=69545#1431550655
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=0765623d6991b62ffcd93ddb6be8a5203a2fa7e2
The #69545 bug was originally fixed in 5.4.41 / 5.5.25 / 5.6.9 and got CVE-2015-4022 (see bug 1223412), but the fix was found to be incomplete, as explained in the upstream bug.
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1234942]
---
As noted in the description, this CVE was assigned to an incomplete
Bugzilla
CVE-2015-4022 php: integer overflow leading to heap overflow when reading FTP file listing
bugzilla·2015-05-20·CVSS 7.5
CVE-2015-4022 [HIGH] CVE-2015-4022 php: integer overflow leading to heap overflow when reading FTP file listing
CVE-2015-4022 php: integer overflow leading to heap overflow when reading FTP file listing
The ftp_genlist() function of the ftp extension is prone to an integer overflow, which may result in remote code execution under certain circumstances.
Upstream report:
https://bugs.php.net/bug.php?id=69545
Upstream fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=ac2832935435556dc593784cd0087b5e576bbe4d
CVE request:
http://seclists.org/oss-sec/2015/q2/479
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1223447]
---
php-5.6.9-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
php-5.6.9-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, ple
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=0765623d6991b62ffcd93ddb6be8a5203a2fa7e2http://openwall.com/lists/oss-security/2015/06/18/6http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1186.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1187.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1218.htmlhttp://www.debian.org/security/2015/dsa-3344http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/75291http://www.securitytracker.com/id/1032709https://bugs.php.net/bug.php?id=69545https://security.gentoo.org/glsa/201606-10http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=0765623d6991b62ffcd93ddb6be8a5203a2fa7e2http://openwall.com/lists/oss-security/2015/06/18/6http://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2015-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1186.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1187.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1218.htmlhttp://www.debian.org/security/2015/dsa-3344http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/75291http://www.securitytracker.com/id/1032709https://bugs.php.net/bug.php?id=69545https://security.gentoo.org/glsa/201606-10
2016-05-16
Published