Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-2331

Опубликовано: 30 мар. 2015
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5

Описание

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

РелизСтатусПримечание
devel

not-affected

1.0.1-0ubuntu1
esm-infra-legacy/trusty

not-affected

0.10.1-1.2
lucid

ignored

end of life
precise

not-affected

0.10-1ubuntu1
trusty

not-affected

0.10.1-1.2
trusty/esm

not-affected

0.10.1-1.2
upstream

released

0.11.2-1.2
utopic

ignored

end of life
vivid

ignored

end of life
vivid/stable-phone-overlay

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.7
lucid

not-affected

5.3.2-1ubuntu4.29
precise

not-affected

5.3.10-1ubuntu3.17
trusty

not-affected

5.5.9+dfsg-1ubuntu4.7
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.7
upstream

needs-triage

utopic

not-affected

5.5.12+dfsg-2ubuntu4.3
vivid

released

5.6.4+dfsg-4ubuntu4
vivid/stable-phone-overlay

DNE

Показывать по

EPSS

Процентиль: 97%
0.4271
Средний

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

nvd
около 10 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

debian
около 10 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libz ...

suse-cvrf
около 10 лет назад

Security update for libzip

github
около 3 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

EPSS

Процентиль: 97%
0.4271
Средний

7.5 High

CVSS2