Lucene search

K
f5F5F5:K16993
HistoryJul 22, 2015 - 12:00 a.m.

K16993 : PHP vulnerabilities CVE-2015-4025 and CVE-2015-4026

2015-07-2200:00:00
my.f5.com
41

8.2 High

AI Score

Confidence

Low

0.04 Low

EPSS

Percentile

92.1%

Security Advisory Description

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
Impact
This vulnerability allows unauthorized disclosure of information, unauthorized modification, and disruption of service.