CVE-2015-4022: Buffer Overflow
Integer overflow in the ftpgenlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4022?
CVE-2015-4022 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2015-4022?
To fix CVE-2015-4022, update PHP to versions 5.4.41, 5.5.25, or 5.6.9 or later.
What are the affected versions for CVE-2015-4022?
CVE-2015-4022 affects PHP versions prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9.
What software is impacted by CVE-2015-4022?
CVE-2015-4022 impacts software that runs vulnerable versions of PHP across various platforms, including Red Hat Enterprise Linux.
Can CVE-2015-4022 be exploited remotely?
Yes, CVE-2015-4022 can be exploited remotely through malicious FTP commands leading to a buffer overflow.