Описание
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | released  | 5.6.9+dfsg-1ubuntu1 | 
| esm-infra-legacy/trusty | released  | 5.5.9+dfsg-1ubuntu4.11 | 
| precise | released  | 5.3.10-1ubuntu3.19 | 
| trusty | released  | 5.5.9+dfsg-1ubuntu4.11 | 
| trusty/esm | released  | 5.5.9+dfsg-1ubuntu4.11 | 
| upstream | released  | 5.4.41,5.5.25,5.6.9 | 
| utopic | released  | 5.5.12+dfsg-2ubuntu4.6 | 
| vivid | released  | 5.6.4+dfsg-4ubuntu6.2 | 
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP b ...
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
Уязвимость функции ftp_genlist интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
EPSS
7.5 High
CVSS2