Integer overflow in PHP - CVE-2015-4022

 

Integer overflow in PHP - CVE-2015-4022

Published: November 27, 2018


Vulnerability identifier: #VU16120
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-4022
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9. A remote attacker can trigger heap-based buffer overflow via a long reply to a LIST command and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

PHP
Amazon Linux AMI
Slackware Linux
Fedora
php5 (Ubuntu package)
php

How to mitigate CVE-2015-4022

Install update from vendor's website.

PHP - addressed in versions 5.4.41, 5.5.25, 5.6.9
php5 (Ubuntu package) - addressed in versions 5.3.10-1ubuntu3.19, 5.5.9+dfsg-1ubuntu4.11, 5.5.12+dfsg-2ubuntu4.6, 5.6.4+dfsg-4ubuntu6.2
php - addressed in versions 5.6.9-1.fc21, 5.6.9-1.fc22

External References

Related Security Bulletins