CVE-2012-2386
PHP 'phar' Extension 1.1.1 - Heap Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.
Desbordamiento de entero en la función phar_parse_tarfile en tar.c en la extensión en PHP v5.4.x anterior a v5.3.14 y v5.4.4 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código arbitrario a través de un alquitrán diseñado archivo que provoca un desbordamiento de búfer basado en heap.
There is a programming error in the DES implementation used in crypt() in ext/standard/crypt_freesec.c when handling input which contains characters that can not be represented with 7-bit ASCII. When the input contains characters with only the most significant bit set (0x80), that character and all characters after it will be ignored. An integer overflow, leading to heap-based buffer overflow was found in the way Phar extension of the PHP scripting language processed certain fields by manipulating TAR files. A remote attacker could provide a specially-crafted TAR archive file, which once processed in an PHP application using the Phar extension could lead to denial of service , or, potentially arbitrary code execution with the privileges of the user running the application. The updated php packages have been upgraded to the 5.3.14 version which is not vulnerable to these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-19 CVE Reserved
- 2012-06-11 CVE Published
- 2015-04-22 First Exploit
- 2024-08-06 CVE Updated
- 2025-08-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-189: Numeric Errors
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=158d8a6b088662ce9d31e0c777c6ebe90efdc854 | X_refsource_confirm | |
http://openwall.com/lists/oss-security/2012/05/22/10 | Mailing List | |
http://support.apple.com/kb/HT5501 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/17201 | 2015-04-22 | |
http://0x1byte.blogspot.com/2011/04/php-phar-extension-heap-overflow.html | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html | 2023-02-13 | |
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html | 2023-02-13 | |
http://www.php.net/ChangeLog-5.php | 2023-02-13 | |
https://bugs.php.net/bug.php?id=61065 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=823594 | 2012-06-27 | |
https://access.redhat.com/security/cve/CVE-2012-2386 | 2012-06-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | <= 5.3.13 Search vendor "Php" for product "Php" and version " <= 5.3.13" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 5.4.0 < 5.4.4 Search vendor "Php" for product "Php" and version " >= 5.4.0 < 5.4.4" | - |
Affected
|