Unrated severityNVD Advisory· Published Dec 11, 2015· Updated Jun 17, 2026
CVE-2015-7804
CVE-2015-7804
Description
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.5.29
- cpe:2.3:a:php:php:5.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*
- (no CPE)range: <5.5.30 || >=5.6.0 <5.6.14
Patches
Vulnerability mechanics
References
12- bugs.php.net/bug.phpnvdVendor Advisory
- support.apple.com/HT205637nvdVendor Advisory
- git.php.netnvd
- lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-01/msg00099.htmlnvd
- www.debian.org/security/2015/dsa-3380nvd
- www.openwall.com/lists/oss-security/2015/10/05/8nvd
- www.php.net/ChangeLog-5.phpnvd
- www.securityfocus.com/bid/76959nvd
- www.slackware.com/security/viewer.phpnvd
- www.ubuntu.com/usn/USN-2786-1nvd
- security.gentoo.org/glsa/201606-10nvd
News mentions
0No linked articles in our index yet.