CVE-2016-6297
published 2016-07-25CVE-2016-6297: Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
5.27%
91.6th percentile
Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sierra | — | — |
| php | php | <= 5.5.37 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gc7r-mm9q-vgrj: Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream
ghsa_unreviewed·2022-05-14
CVE-2016-6297 [HIGH] CWE-119 GHSA-gc7r-mm9q-vgrj: Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream
Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.
OSV
php5, php7.0 vulnerabilities
osv·2016-08-02·CVSS 9.8
CVE-2015-4116 [CRITICAL] php5, php7.0 vulnerabilities
php5, php7.0 vulnerabilities
It was discovered that PHP incorrectly handled certain SplMinHeap::compare
operations. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-4116)
It was discovered that PHP incorrectly handled recursive method calls. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2015-8873)
It was discovered that PHP incorrectly validated certain Exception objects
when unserializing data. A remote attacker could use this issue to cause
PHP to crash, resulting in a denial of service, or possibly execute
arbitr
OSV
CVE-2016-6297: Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream
osv·2016-07-25·CVSS 8.8
CVE-2016-6297 [HIGH] CVE-2016-6297: Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream
Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.
Apple
CVE-2016-6297: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 8.8
CVE-2016-6297 [HIGH] CVE-2016-6297: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-6297
Component: CVE-2016-6297
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2016-08-02·CVSS 9.8
CVE-2015-4116 [CRITICAL] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain SplMinHeap::compare
operations. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-4116)
It was discovered that PHP incorrectly handled recursive method calls. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2015-8873)
It was discovered that PHP incorrectly validated certain Exception objects
when unserializing data. A remote attacker could use this issue to cause
PHP to crash, resulting
Red Hat
php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
vendor_redhat·2016-06-30·CVSS 8.8
CVE-2016-6297 [HIGH] CWE-121 php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collections) - Will not fix
No detection rules found.
No public exploits indexed.
Fortinet
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
blogs_fortinet·2018-05-04
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
FORTIGUARD LABS THREAT RESEARCH
GandCrab V3 Accidentally Locks Systems with New ‘Change Wallpaper’ Feature
By Joie Salvio | May 04, 2018
GandCrab is one of the most talked about ransomware families this year primarily due to its increasing distribution volume, as we described in our previous article. At the end of last month, FortiGuard Labs discovered a new spam wave from the same campaign delivering the latest version, GandCrab v3.
In this new version, following in the footsteps of past infamous ransomware families such as Locky and Sage, this latest version now also changes the wallpapers of its victims. However, when we analyzed this new feature we found a bug that can be detrimental to its goals, as well as more frustrating to its unfortunate victims.
New Spam Wave, Same Old Trick
Fortinet
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
blogs_fortinet·2018-01-12
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
FORTIGUARD LABS THREAT RESEARCH
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
By Minh Tran | January 12, 2018
Introduction
2018 truly is starting off with a bang: fundamental CPU flaws dubbed Meltdown and Spectre were found affecting pretty much all modern processors developed since the Pentium Pro (1995). These flaws root in two critical CPU features: Out of Order Execution and Speculative Execution, which are crucial for performance. Since this is an important feature and not a bug, it is inherently hard to fix. Furthermore, for performance reasons, speculative execution is almost always implemented in hardware, so “fixes” tend toward mitigations (e.g. microcode updates).
Due to the serious nature of these flaws,
Fortinet
Joomla – From Nowhere to High Privilege
blogs_fortinet·2016-10-27·CVSS 9.8
CVE-2016-8870 [CRITICAL] Joomla – From Nowhere to High Privilege
FORTIGUARD LABS THREAT RESEARCH
Joomla – From Nowhere to High Privilege
By Tien Phan | October 27, 2016
Joomla, a popular free and open-source content management system, just released version 3.6.4 that fixed two critical vulnerabilities:
[CVE-2016-8870] - Core - Account Creation: attackers can exploit this vulnerability to create any account in a Joomla system regardless of whether its registration has been disabled.
[CVE-2016-8869] - Core - Elevated Privileges: with the vulnerability above, an attacker not only can register an account in a vulnerable system, but also register with the highest privilege – Administrator.
We took a deeper dive to see how these exploits tick and would like to congratulate Davide Tampellini on his first CVE discovery.
CVE-2016-8870 - From no one to havin
Fortinet
Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
blogs_fortinet·2016-08-10·CVSS 4.3
CVE-2016-6289 [MEDIUM] Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
FORTIGUARD LABS THREAT RESEARCH
Analysis of PHP's CVE-2016-6289 and CVE-2016-6297
By Tony Loi | August 10, 2016
PHP is a programming language that was created in 1995 by Rasmus Lerdorf. And according to W3Techs, it’s dynamically generating content on more than 82% of all websites worldwide. That means hundreds of millions of web servers are vulnerable to the flaws we are describing below.
Last month, FortiGuard discovered two security issues in PHP’s core (CVE-2016-6189) and in PHP’s zip (CVE-2016-6197). These issues affect both the current PHP version 5 and its upcoming version 7. These bugs are located in different part of the code, and feature different functionalities, but they share the same type:
Integer overflow
Stack-based buffer overflow
A well-trained eye can identify these
Bugzilla
CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
bugzilla·2016-07-25·CVSS 7.8
CVE-2016-6289 [HIGH] CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2016-6297 php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
bugzilla·2016-07-25·CVSS 8.8
CVE-2016-6297 [HIGH] CVE-2016-6297 php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
CVE-2016-6297 php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
It was found that when opening a zip stream, php_stream_zip_opener fails to check the path_len that is vulnerable to integer overflow. It is later used to calculate the length of mempcy that can lead to buffer overflow and memory corruption.
Upstream bug:
https://bugs.php.net/bug.php?id=72520
Upstream patch:
http://git.php.net/?p=php-src.git;a=commit;h=81406c0c1d45f75fcc7972ed974d2597abb0b9e9
CVE assignment:
http://seclists.org/oss-sec/2016/q3/137
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1359837]
---
The affected function has to be used in a very specific way. It's unlikely that this function is used in a way that lends it to exploitation.
Compile time bu
http://fortiguard.com/advisory/fortinet-discovers-php-stack-based-buffer-overflow-vulnerabilitieshttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=81406c0c1d45f75fcc7972ed974d2597abb0b9e9http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://openwall.com/lists/oss-security/2016/07/24/2http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3631http://www.securityfocus.com/bid/92099http://www.securitytracker.com/id/1036430https://bugs.php.net/72520https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT207170http://fortiguard.com/advisory/fortinet-discovers-php-stack-based-buffer-overflow-vulnerabilitieshttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=81406c0c1d45f75fcc7972ed974d2597abb0b9e9http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://openwall.com/lists/oss-security/2016/07/24/2http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3631http://www.securityfocus.com/bid/92099http://www.securitytracker.com/id/1036430https://bugs.php.net/72520https://security.gentoo.org/glsa/201611-22https://support.apple.com/HT207170
2016-07-25
Published