// For flags

CVE-2015-7803

php: NULL pointer dereference in phar_get_fp_offset()

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.

La función phar_get_entry_data en ext/phar/util.c en PHP en versiones anteriores a 5.5.30 y 5.6.x en versiones anteriores a 5.6.14 permite a atacantes remotos causar una denegación de servicio (referencia a puntero NULL y caída de aplicación) a través de un archivo .phar con una entrada de archivo TAR manipulada en la cual el indicador Link referencia a un archivo que no existe.

A flaw was found in the way the way PHP's Phar extension parsed Phar archives. A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened.

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Multiple flaws were discovered in the way PHP performed object unserialization. Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code. Multiple flaws were found in the way the way PHP's Phar extension parsed Phar archives. A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-10-09 CVE Reserved
  • 2015-10-28 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-04-10 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-476: NULL Pointer Dereference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.5.29
Search vendor "Php" for product "Php" and version " <= 5.5.29"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.1
Search vendor "Php" for product "Php" and version "5.6.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.2
Search vendor "Php" for product "Php" and version "5.6.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.3
Search vendor "Php" for product "Php" and version "5.6.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.4
Search vendor "Php" for product "Php" and version "5.6.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.5
Search vendor "Php" for product "Php" and version "5.6.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.6
Search vendor "Php" for product "Php" and version "5.6.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.7
Search vendor "Php" for product "Php" and version "5.6.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.8
Search vendor "Php" for product "Php" and version "5.6.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.9
Search vendor "Php" for product "Php" and version "5.6.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.10
Search vendor "Php" for product "Php" and version "5.6.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.11
Search vendor "Php" for product "Php" and version "5.6.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.12
Search vendor "Php" for product "Php" and version "5.6.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.13
Search vendor "Php" for product "Php" and version "5.6.13"
-
Affected
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
<= 10.11.1
Search vendor "Apple" for product "Mac Os X" and version " <= 10.11.1"
-
Affected