← Back

CVE-2015-3307

nvd nist
Published: Jun 9, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.

Affected (58)

7 products
Enterprise Linux Desktop
Enterprise Linux Hpc Node
Enterprise Linux Hpc Node Eus
Enterprise Linux Server
Enterprise Linux Server Eus
Enterprise Linux Workstation
Enterprise Linux
1 product
Mac Os X
1 product
Php
Configuration A
6 vulnerable
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 10.10.4
Configuration E
49 vulnerable
Vulnerable SoftwareAffected Versions
Php
Up to 5.4.39
Version 5.5.0
Version 5.5.0 alpha1
Version 5.5.0 alpha2
Version 5.5.0 alpha3
Version 5.5.0 alpha4
Version 5.5.0 alpha5
Version 5.5.0 alpha6
Version 5.5.0 beta1
Version 5.5.0 beta2
Version 5.5.0 beta3
Version 5.5.0 beta4
Version 5.5.0 rc1
Version 5.5.0 rc2
Version 5.5.10
Version 5.5.11
Version 5.5.12
Version 5.5.13
Version 5.5.14
Version 5.5.18
Version 5.5.19
Version 5.5.1
Version 5.5.20
Version 5.5.21
Version 5.5.22
Version 5.5.23
Version 5.5.2
Version 5.5.3
Version 5.5.4
Version 5.5.5
Version 5.5.6
Version 5.5.7
Version 5.5.8
Version 5.5.9
Version 5.6.0 alpha1
Version 5.6.0 alpha2
Version 5.6.0 alpha3
Version 5.6.0 alpha4
Version 5.6.0 alpha5
Version 5.6.0 beta1
Version 5.6.0 beta2
Version 5.6.0 beta3
Version 5.6.0 beta4
Version 5.6.2
Version 5.6.3
Version 5.6.4
Version 5.6.5
Version 5.6.6
Version 5.6.7

References (22)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.