CVE-2015-4643: Buffer Overflow
Integer overflow in the ftpgenlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4643?
CVE-2015-4643 has been classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2015-4643?
To fix CVE-2015-4643, update PHP to version 5.4.42 or later, 5.5.26 or later, or 5.6.10 or later.
Which PHP versions are affected by CVE-2015-4643?
CVE-2015-4643 affects PHP versions prior to 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10.
What are the potential impacts of CVE-2015-4643?
The vulnerability can lead to a heap-based buffer overflow, allowing remote FTP servers to execute arbitrary code.
Are any Linux distributions affected by CVE-2015-4643?
Yes, Debian and Red Hat enterprise Linux distributions are among those affected by CVE-2015-4643, depending on the versions used.