← All CVEs

CVE-2015-7803

medium · 6.8

The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.

6.8
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2015-12-11
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
phpphp<= 5.5.29
phpphp5.6.1
phpphp5.6.2
phpphp5.6.3
phpphp5.6.4
phpphp5.6.5
phpphp5.6.6
phpphp5.6.7
phpphp5.6.8
phpphp5.6.9
phpphp5.6.10
phpphp5.6.11
phpphp5.6.12
phpphp5.6.13
applemac_os_x<= 10.11.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-7803