CVE-2015-2331: Buffer Overflow
Integer overflow in the zipcdirnew function in zipdirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2331?
The severity of CVE-2015-2331 is considered to be high due to the potential for denial of service and possible remote code execution.
How do I fix CVE-2015-2331?
To fix CVE-2015-2331, update the affected software to a version that is not susceptible to this vulnerability, such as libzip version 0.11.3 or later, or PHP versions 5.4.39, 5.5.23, or 5.6.7 and later.
Who is affected by CVE-2015-2331?
CVE-2015-2331 affects users of libzip versions up to 0.11.2 and PHP versions before 5.4.39, as well as various other products reliant on these libraries.
What kind of attack can be executed with CVE-2015-2331?
CVE-2015-2331 can be exploited to crash applications, causing denial of service, and could potentially lead to remote code execution under certain conditions.
When was CVE-2015-2331 discovered?
CVE-2015-2331 was publicly disclosed in 2015.