CVE-2016-6289
published 2016-07-25CVE-2016-6289: Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote…
PriorityP339high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.79%
88.8th percentile
Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sierra | — | — |
| php | php | <= 5.5.37 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-6289: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 7.8
CVE-2016-6289 [HIGH] CVE-2016-6289: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-6289
Component: CVE-2016-6289
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2016-08-02·CVSS 9.8
CVE-2015-4116 [CRITICAL] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain SplMinHeap::compare
operations. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-4116)
It was discovered that PHP incorrectly handled recursive method calls. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2015-8873)
It was discovered that PHP incorrectly validated certain Exception objects
when unserializing data. A remote attacker could use this issue to cause
PHP to crash, resulting
Red Hat
php: Integer overflow leads to buffer overflow in virtual_file_ex
vendor_redhat·2016-06-29·CVSS 7.8
CVE-2016-6289 [HIGH] CWE-190 php: Integer overflow leads to buffer overflow in virtual_file_ex
php: Integer overflow leads to buffer overflow in virtual_file_ex
Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collections) - Will not fix
GHSA
GHSA-5r2j-74cf-87hv: Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd
ghsa_unreviewed·2022-05-14
CVE-2016-6289 [HIGH] CWE-190 GHSA-5r2j-74cf-87hv: Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd
Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.
OSV
php5, php7.0 vulnerabilities
osv·2016-08-02·CVSS 9.8
CVE-2015-4116 [CRITICAL] php5, php7.0 vulnerabilities
php5, php7.0 vulnerabilities
It was discovered that PHP incorrectly handled certain SplMinHeap::compare
operations. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-4116)
It was discovered that PHP incorrectly handled recursive method calls. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2015-8873)
It was discovered that PHP incorrectly validated certain Exception objects
when unserializing data. A remote attacker could use this issue to cause
PHP to crash, resulting in a denial of service, or possibly execute
arbitr
OSV
CVE-2016-6289: Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd
osv·2016-07-25·CVSS 7.8
CVE-2016-6289 [HIGH] CVE-2016-6289: Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd
Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.
No detection rules found.
No public exploits indexed.
Fortinet
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
blogs_fortinet·2018-05-04
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
FORTIGUARD LABS THREAT RESEARCH
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
By Joie Salvio | May 04, 2018
GandCrab is one of the most talked about ransomware families this year primarily due to its increasing distribution volume, as we described in our previous article. At the end of last month, FortiGuard Labs discovered a new spam wave from the same campaign delivering the latest version, GandCrab v3.
In this new version, following in the footsteps of past infamous ransomware families such as Locky and Sage, this latest version now also changes the wallpapers of its victims. However, when we analyzed this new feature we found a bug that can be detrimental to its goals, as well as more frustrating to its unfortunate victims.
New Spam Wave, Same Old Trick
Fortinet
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
blogs_fortinet·2018-01-12
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
FORTIGUARD LABS THREAT RESEARCH
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
By Minh Tran | January 12, 2018
Introduction
2018 truly is starting off with a bang: fundamental CPU flaws dubbed Meltdown and Spectre were found affecting pretty much all modern processors developed since the Pentium Pro (1995). These flaws root in two critical CPU features: Out of Order Execution and Speculative Execution, which are crucial for performance. Since this is an important feature and not a bug, it is inherently hard to fix. Furthermore, for performance reasons, speculative execution is almost always implemented in hardware, so “fixes” tend toward mitigations (e.g. microcode updates).
Due to the serious nature of these flaws,
Fortinet
Joomla – From Nowhere to High Privilege
blogs_fortinet·2016-10-27·CVSS 9.8
CVE-2016-8870 [CRITICAL] Joomla – From Nowhere to High Privilege
FORTIGUARD LABS THREAT RESEARCH
Joomla – From Nowhere to High Privilege
By Tien Phan | October 27, 2016
Joomla, a popular free and open-source content management system, just released version 3.6.4 that fixed two critical vulnerabilities:
[CVE-2016-8870] - Core - Account Creation: attackers can exploit this vulnerability to create any account in a Joomla system regardless of whether its registration has been disabled.
[CVE-2016-8869] - Core - Elevated Privileges: with the vulnerability above, an attacker not only can register an account in a vulnerable system, but also register with the highest privilege – Administrator.
We took a deeper dive to see how these exploits tick and would like to congratulate Davide Tampellini on his first CVE discovery.
CVE-2016-8870 - From no one to havin
Fortinet
Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
blogs_fortinet·2016-08-10·CVSS 4.3
CVE-2016-6289 [MEDIUM] Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
FORTIGUARD LABS THREAT RESEARCH
Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
By Tony Loi | August 10, 2016
PHP is a programming language that was created in 1995 by Rasmus Lerdorf. And according to W3Techs, it’s dynamically generating content on more than 82% of all websites worldwide. That means hundreds of millions of web servers are vulnerable to the flaws we are describing below.
Last month, FortiGuard discovered two security issues in PHP’s core (CVE-2016-6189) and in PHP’s zip (CVE-2016-6197). These issues affect both the current PHP version 5 and its upcoming version 7. These bugs are located in different part of the code, and feature different functionalities, but they share the same type:
Integer overflow
Stack-based buffer overflow
A well-trained eye can identify these
Bugzilla
CVE-2016-6289 php: Integer overflow leads to buffer overflow in virtual_file_ex
bugzilla·2016-07-25·CVSS 7.8
CVE-2016-6289 [HIGH] CVE-2016-6289 php: Integer overflow leads to buffer overflow in virtual_file_ex
CVE-2016-6289 php: Integer overflow leads to buffer overflow in virtual_file_ex
An integer overflow vulnerability was found in CWD_API virtual_file_ex in php-src/Zend/zend_virtual_cwd.c that allows to memcpy a large chunk of memory leading to buffer overflow.
Upstream bug:
https://bugs.php.net/bug.php?id=72513
Upstream patch:
http://git.php.net/?p=php-src.git;a=commit;h=0218acb7e756a469099c4ccfb22bce6c2bd1ef87
CVE assignment:
http://seclists.org/oss-sec/2016/q3/137
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1359837]
---
Analysis:
This is a flaw in the Thread Safe Resource Manager virtual_file_ex() function of PHP, which is defined as:
CWD_API int virtual_file_ex(cwd_state *state, const char *path, verify_path_func verify_path, int use_realp
Bugzilla
CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
bugzilla·2016-07-25·CVSS 7.8
CVE-2016-6289 [HIGH] CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
http://fortiguard.com/advisory/fortinet-discovers-php-stack-based-buffer-overflow-vulnerabilitieshttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=0218acb7e756a469099c4ccfb22bce6c2bd1ef87http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://openwall.com/lists/oss-security/2016/07/24/2http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3631http://www.securityfocus.com/bid/92074http://www.securitytracker.com/id/1036430https://bugs.php.net/72513https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT207170http://fortiguard.com/advisory/fortinet-discovers-php-stack-based-buffer-overflow-vulnerabilitieshttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=0218acb7e756a469099c4ccfb22bce6c2bd1ef87http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://openwall.com/lists/oss-security/2016/07/24/2http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3631http://www.securityfocus.com/bid/92074http://www.securitytracker.com/id/1036430https://bugs.php.net/72513https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT207170
2016-07-25
Published