CVE-2016-4072
published 2016-05-20CVE-2016-4072: The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as…
PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.93%
92.4th percentile
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.4 | — |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2016-05-24·CVSS 7.3
CVE-2015-8865 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that the PHP Fileinfo component incorrectly handled
certain magic files. An attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)
Hans Jerry Illikainen discovered that the PHP Zip extension incorrectly
handled certain malformed Zip archives. A remote attacker could use this
issue to cause PHP to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-3078)
It was discovered that PHP incorrectly handled invalid indexes in the
SplDoublyLinkedList class. An attacker could use this issue to cause
Red Hat
php: Invalid memory write in phar on filename containing \0 inside name
vendor_redhat·2016-03-19·CVSS 9.8
CVE-2016-4072 [CRITICAL] CWE-787 php: Invalid memory write in phar on filename containing \0 inside name
php: Invalid memory write in phar on filename containing \0 inside name
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collections) - Will not fix
Apple
CVE-2016-4072: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 9.8
CVE-2016-4072 [CRITICAL] CVE-2016-4072: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-4072
Component: CVE-2016-4072
GHSA
GHSA-j2xj-f75j-96w3: The Phar extension in PHP before 5
ghsa_unreviewed·2022-05-14
CVE-2016-4072 [CRITICAL] CWE-20 GHSA-j2xj-f75j-96w3: The Phar extension in PHP before 5
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
OSV
php5, php7.0 vulnerabilities
osv·2016-05-24·CVSS 7.3
CVE-2015-8865 [HIGH] php5, php7.0 vulnerabilities
php5, php7.0 vulnerabilities
It was discovered that the PHP Fileinfo component incorrectly handled
certain magic files. An attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)
Hans Jerry Illikainen discovered that the PHP Zip extension incorrectly
handled certain malformed Zip archives. A remote attacker could use this
issue to cause PHP to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-3078)
It was discovered that PHP incorrectly handled invalid indexes in the
SplDoublyLinkedList class. An attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or
OSV
CVE-2016-4072: The Phar extension in PHP before 5
osv·2016-04-25·CVSS 9.8
CVE-2016-4072 [CRITICAL] CVE-2016-4072: The Phar extension in PHP before 5
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name [fedora-all]
bugzilla·2016-04-01·CVSS 9.8
CVE-2016-4072 [CRITICAL] CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name [fedora-all]
CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name
bugzilla·2016-04-01·CVSS 9.8
CVE-2016-4072 [CRITICAL] CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name
CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name
An invalid write vulnerability causing segmentation fault in phar on filename with \0 inside its name was found.
Vulnerable code (phar_analyze_path):
if (!(realpath = expand_filepath(filename, NULL))) {
efree(filename);
return FAILURE;
}
#ifdef PHP_WIN32
phar_unixify_path_separators(realpath, strlen(realpath));
#endif
slash = strstr(realpath, filename);
if (slash) {
slash += ((ext - fname) + ext_len);
*slash = '\0';
}
If fname and thus filename contain \0's, realpath would not contain those parts and thus slash would point past the end of the realpath buffer.
To exploit this, application has to allow attacker to create phar files with arbitrary filenames.
Upstream bug:
https://bugs.php.net/bug.php?
http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3560http://www.openwall.com/lists/oss-security/2016/04/24/1http://www.php.net/ChangeLog-5.phphttp://www.php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/85993http://www.ubuntu.com/usn/USN-2952-1http://www.ubuntu.com/usn/USN-2952-2https://bugs.php.net/bug.php?id=71860https://gist.github.com/smalyshev/80b5c2909832872f2ba2https://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1e9b175204e3286d64dfd6c9f09151c31b5e099ahttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT206567http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3560http://www.openwall.com/lists/oss-security/2016/04/24/1http://www.php.net/ChangeLog-5.phphttp://www.php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/85993http://www.ubuntu.com/usn/USN-2952-1http://www.ubuntu.com/usn/USN-2952-2https://bugs.php.net/bug.php?id=71860https://gist.github.com/smalyshev/80b5c2909832872f2ba2https://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1e9b175204e3286d64dfd6c9f09151c31b5e099ahttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT206567
2016-05-20
Published