CVE-2015-3307
Published: 9 June 2015
The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.
Notes
Author | Note |
---|---|
mdeslaur | The two first commits may have also been used to fix CVE-2015-2783 |
Priority
Status
Package | Release | Status |
---|---|---|
php5 Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
(5.3.10-1ubuntu3.18)
|
trusty |
Not vulnerable
(5.5.9+dfsg-1ubuntu4.9)
|
|
upstream |
Released
(5.4.40,5.5.24,5.6.8)
|
|
utopic |
Not vulnerable
(5.5.12+dfsg-2ubuntu4.4)
|
|
vivid |
Not vulnerable
(5.6.4+dfsg-4ubuntu6)
|
|
Patches: upstream: http://git.php.net/?p=php-src.git;a=commit;h=17cbd0b5b78a7500f185b3781a2149881bfff8ae upstream: http://git.php.net/?p=php-src.git;a=commit;h=9faaee66fa493372c7340b1ab05f8fd115131a42 upstream: http://git.php.net/?p=php-src.git;a=commit;h=12d3bdee3dfa6605024a72080d8a17c165c5ed24 upstream: http://git.php.net/?p=php-src.git;a=commit;h=cee97220285fd7b955a58617b3e0300ec104ed87 upstream: http://git.php.net/?p=php-src.git;a=commit;h=be504995c351a2582e82b52bd4e0383e9e27783d |