CVE Vulnerabilities

CVE-2015-4644

Published: May 16, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat6.0 (including)6.0 (including)
Enterprise_linuxRedhat7.0 (including)7.0 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatphp55-php-0:5.5.21-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-php-0:5.6.5-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatphp54-php-0:5.4.40-3.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSRedHatphp55-php-0:5.5.21-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSRedHatrh-php56-php-0:5.6.5-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSRedHatphp54-php-0:5.4.40-3.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatphp55-php-0:5.5.21-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-php56-php-0:5.6.5-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatphp54-php-0:5.4.40-3.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatphp55-php-0:5.5.21-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-php-0:5.6.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatphp54-php-0:5.4.40-3.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatphp55-php-0:5.5.21-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-php56-php-0:5.6.5-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatphp54-php-0:5.4.40-3.el7*
Php5Ubuntudevel*
Php5Ubuntuesm-infra-legacy/trusty*
Php5Ubuntuprecise*
Php5Ubuntutrusty*
Php5Ubuntutrusty/esm*
Php5Ubuntuupstream*
Php5Ubuntuutopic*
Php5Ubuntuvivid*

References