Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3142

Опубликовано: 31 мар. 2016
Источник: debian
EPSS Низкий

Описание

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.6.19+dfsg-1package
php5fixed5.6.19+dfsg-0+deb8u1jessiepackage
php5no-dsawheezypackage

Примечания

  • https://bugs.php.net/bug.php?id=71498

  • Fixed in 5.5.33, 5.6.19

  • https://www.openwall.com/lists/oss-security/2016/03/10/5

  • https://www.openwall.com/lists/oss-security/2016/03/13/2

  • https://git.php.net/?p=php-src.git;a=commit;h=a6fdc5bb27b20d889de0cd29318b3968aabb57bd

EPSS

Процентиль: 82%
0.0178
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 9 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

redhat
больше 9 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
nvd
больше 9 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
github
больше 3 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

fstec
больше 9 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю получить конфиденциальную информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 82%
0.0178
Низкий