Vulnerability Description
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nih | Libzip | <= 0.11.2 |
| Php | Php | <= 5.4.38 |
| Debian | Debian Linux | 7.0 |
| Fedoraproject | Fedora | 22 |
| Opensuse | Opensuse | 13.1 |
Related Weaknesses (CWE)
References
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=ef8fc4b53d92fbfcd8ef1abbd6f2f5f
- http://hg.nih.at/libzip/rev/9f11d54f692eVendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154266.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154276.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154666.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155299.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155622.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153983.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00083.html
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00002.html
- http://marc.info/?l=bugtraq&m=143403519711434&w=2
- http://marc.info/?l=bugtraq&m=143748090628601&w=2
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://php.net/ChangeLog-5.php
FAQ
What is CVE-2015-2331?
CVE-2015-2331 is a vulnerability with a CVSS score of 7.5 (HIGH). Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other pr...
How severe is CVE-2015-2331?
CVE-2015-2331 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2331?
Check the references section above for vendor advisories and patch information. Affected products include: Nih Libzip, Php Php, Debian Debian Linux, Fedoraproject Fedora, Opensuse Opensuse.