Attack (Attack ID:320133)

Release Date2015/05/12

Attack NameWEB PHP Group PHP ZIP Integer Overflow (CVE-2015-2331)

Severity

BUG ID

CVE ID

 

Description

A heap buffer overflow vulnerability exists in PHP. The vulnerability is due to an integer overflow in the libzip component of PHP and can be used to write beyond the end of a heap buffer.
Impact:Remote code execution
Affected System:Windows, Linux, Other Unix
Additional References:CVE-2015-2331

 

Solution

Update vendor's patch.