CVE
- Id
- 79608
- CVE No.
- CVE-2015-2331
- Status
- Candidate
- Description
- Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.
- Phase
- Assigned (20150318)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
722648 | 79608 | CVE-2015-2331 | CONFIRM:http://git.php.net/?p=php-src.git;a=commit;h=ef8fc4b53d92fbfcd8ef1abbd6f2f5fe2c4a11e5 | View |
722649 | 79608 | CVE-2015-2331 | CONFIRM:http://hg.nih.at/libzip/rev/9f11d54f692e | View |
722650 | 79608 | CVE-2015-2331 | CONFIRM:http://php.net/ChangeLog-5.php | View |
722651 | 79608 | CVE-2015-2331 | CONFIRM:https://bugs.php.net/bug.php?id=69253 | View |
722652 | 79608 | CVE-2015-2331 | CONFIRM:https://support.apple.com/HT205267 | View |
722653 | 79608 | CVE-2015-2331 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html | View |
722654 | 79608 | CVE-2015-2331 | APPLE:APPLE-SA-2015-09-30-3 | View |
722655 | 79608 | CVE-2015-2331 | URL:http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html | View |
722656 | 79608 | CVE-2015-2331 | DEBIAN:DSA-3198 | View |
722657 | 79608 | CVE-2015-2331 | URL:http://www.debian.org/security/2015/dsa-3198 | View |
722658 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4559 | View |
722659 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153983.html | View |
722660 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4565 | View |
722661 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154266.html | View |
722662 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4669 | View |
722663 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154276.html | View |
722664 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4553 | View |
722665 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154666.html | View |
722666 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4556 | View |
722667 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155299.html | View |
722668 | 79608 | CVE-2015-2331 | FEDORA:FEDORA-2015-4699 | View |
722669 | 79608 | CVE-2015-2331 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155622.html | View |
722670 | 79608 | CVE-2015-2331 | HP:HPSBMU03380 | View |
722671 | 79608 | CVE-2015-2331 | URL:http://marc.info/?l=bugtraq&m=143748090628601&w=2 | View |
722672 | 79608 | CVE-2015-2331 | HP:HPSBMU03409 | View |
722673 | 79608 | CVE-2015-2331 | URL:http://marc.info/?l=bugtraq&m=144050155601375&w=2 | View |
722674 | 79608 | CVE-2015-2331 | HP:HPSBUX03337 | View |
722675 | 79608 | CVE-2015-2331 | URL:http://marc.info/?l=bugtraq&m=143403519711434&w=2 | View |
722676 | 79608 | CVE-2015-2331 | HP:SSRT102066 | View |
722677 | 79608 | CVE-2015-2331 | URL:http://marc.info/?l=bugtraq&m=143403519711434&w=2 | View |
722678 | 79608 | CVE-2015-2331 | MANDRIVA:MDVSA-2015:079 | View |
722679 | 79608 | CVE-2015-2331 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2015:079 | View |
722680 | 79608 | CVE-2015-2331 | SUSE:openSUSE-SU-2015:0615 | View |
722681 | 79608 | CVE-2015-2331 | URL:http://lists.opensuse.org/opensuse-updates/2015-03/msg00083.html | View |
722682 | 79608 | CVE-2015-2331 | SUSE:openSUSE-SU-2015:0644 | View |
722683 | 79608 | CVE-2015-2331 | URL:http://lists.opensuse.org/opensuse-updates/2015-04/msg00002.html | View |
722684 | 79608 | CVE-2015-2331 | SECTRACK:1031985 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
8273 | JVNDB-2015-003593 | Microsoft Internet Explorer 11 における任意のコードを実行される脆弱性 | Microsoft Internet Explorer 11 には、任意のコードを実行される、またはサービス運用妨害 (メモリ破損) 状態にされる脆弱性が存在します。 | CVE-2015-2383 | 79608 | 9.3 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-003593.html | View |