CVE-2015-3329: Buffer Overflow
Multiple stack-based buffer overflows in the pharsetinode function in pharinternal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3329?
CVE-2015-3329 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2015-3329?
To fix CVE-2015-3329, upgrade PHP to version 5.4.40 or later, 5.5.24 or later, or 5.6.8 or later.
What impact does CVE-2015-3329 have?
CVE-2015-3329 can allow remote attackers to execute arbitrary code on the affected systems.
Which PHP versions are affected by CVE-2015-3329?
Versions of PHP prior to 5.4.40, 5.5.24, and 5.6.8 are affected by CVE-2015-3329.
Are there any workarounds for CVE-2015-3329?
Temporary workarounds for CVE-2015-3329 include disabling the phar extension or restricting access to vulnerable PHP scripts.