Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-3307

Published: 9 June 2015

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.

Notes

AuthorNote
mdeslaur
The two first commits may have also been used to fix
CVE-2015-2783

Priority

Low

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
precise Not vulnerable
(5.3.10-1ubuntu3.18)
trusty Not vulnerable
(5.5.9+dfsg-1ubuntu4.9)
upstream
Released (5.4.40,5.5.24,5.6.8)
utopic Not vulnerable
(5.5.12+dfsg-2ubuntu4.4)
vivid Not vulnerable
(5.6.4+dfsg-4ubuntu6)
Patches:
upstream: http://git.php.net/?p=php-src.git;a=commit;h=17cbd0b5b78a7500f185b3781a2149881bfff8ae
upstream: http://git.php.net/?p=php-src.git;a=commit;h=9faaee66fa493372c7340b1ab05f8fd115131a42
upstream: http://git.php.net/?p=php-src.git;a=commit;h=12d3bdee3dfa6605024a72080d8a17c165c5ed24
upstream: http://git.php.net/?p=php-src.git;a=commit;h=cee97220285fd7b955a58617b3e0300ec104ed87
upstream: http://git.php.net/?p=php-src.git;a=commit;h=be504995c351a2582e82b52bd4e0383e9e27783d