Heap-based buffer overflow in Debian products - CVE-2015-2331
Published: March 30, 2015 / Updated: August 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products,. A remote attacker can use a ZIP archive that contains many entries to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
Debian Linux
Amazon Linux AMI
Slackware Linux
PHP
mingw-libzip
libzip
php
How to mitigate CVE-2015-2331
libzip - addressed in versions 0.11.2-5.fc21, 0.11.2-5.fc22
php - addressed in versions 5.6.7-1.fc21, 5.6.7-2.fc22
External References
- http://git.php.net/?p=php-src.git;a=commit;h=ef8fc4b53d92fbfcd8ef1abbd6f2f5fe2c4a11e5
- http://hg.nih.at/libzip/rev/9f11d54f692e
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154266.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154276.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154666.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155299.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155622.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153983.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00083.html
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00002.html
- http://marc.info/?l=bugtraq&m=143403519711434&w=2
- http://marc.info/?l=bugtraq&m=143748090628601&w=2
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://php.net/ChangeLog-5.php
- http://www.debian.org/security/2015/dsa-3198
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:079
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- http://www.securitytracker.com/id/1031985
- https://bugs.php.net/bug.php?id=69253
- https://support.apple.com/HT205267
Related Security Bulletins
- Amazon Linux AMI update for php56
- Amazon Linux AMI update for php55
- Amazon Linux AMI update for php54
- Slackware Linux update for php
- Fedora 22 update for php
- Fedora 21 update for php
- Fedora 22 update for libzip
- Fedora 21 update for libzip
- Fedora 22 update for mingw-libzip
- Fedora 21 update for mingw-libzip