CVE-2015-5590: Buffer Overflow
Stack-based buffer overflow in the pharfixfilepath function in ext/phar/phar.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value, as demonstrated by mishandling of an e-mail attachment by the imap PHP extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5590?
CVE-2015-5590 has a high severity level due to the potential for remote attackers to cause a denial of service.
How do I fix CVE-2015-5590?
To mitigate CVE-2015-5590, upgrade PHP to versions 5.4.43, 5.5.27, or 5.6.11 or later.
What systems are affected by CVE-2015-5590?
CVE-2015-5590 affects PHP versions prior to 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11.
What attack vectors are associated with CVE-2015-5590?
CVE-2015-5590 allows remote attackers to exploit a stack-based buffer overflow via a large length value.
Is there a workaround for CVE-2015-5590 if I cannot update PHP?
There are no reliable workarounds for CVE-2015-5590, so upgrading PHP is the recommended approach.