CVE-2015-6833

HIGH

PHP < 5.4.44, 5.5.x < 5.5.28, 5.6.x < 5.6.12 - Path Traversal and Arbitrary File Write via PharData extractTo

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3344
Various Sources x_refsource_confirm
https://bugs.php.net/bug.php?id=70019
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/08/19/3
Vendor Advisory x_refsource_confirm
http://www.php.net/ChangeLog-5.php
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201606-10

Scores

CVSS v3 7.5
EPSS 0.0040
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (30)
php/php 5.5.0 (13 CPE variants)
php/php 5.5.1
php/php 5.5.2
php/php 5.5.3
php/php 5.5.4
php/php 5.5.5
php/php 5.5.6
php/php 5.5.7
php/php 5.5.8
php/php 5.5.9
... and 20 more
Published Jan 19, 2016
Tracked Since Feb 18, 2026