CVE-2015-2301
30.03.2015, 10:59
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| debian | debian_linux | 7.0 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
| php | php | 5.4.0 ≤ 𝑥 < 5.4.40 |
| php | php | 5.5.0 ≤ 𝑥 < 5.5.22 |
| php | php | 5.6.0 ≤ 𝑥 < 5.6.6 |
| apple | mac_os_x | 𝑥 ≤ 10.10.4 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_hpc_node | 7.0 |
| redhat | enterprise_linux_hpc_node_eus | 7.1 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.1 |
| redhat | enterprise_linux_workstation | 7.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References