CVE-2015-4644
Summary
| CVE | CVE-2015-4644 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-05-16 10:59:16 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-Other | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 5.5.0 | All | All | All |
| Application | Php | Php | 5.5.1 | All | All | All |
| Application | Php | Php | 5.5.10 | All | All | All |
| Application | Php | Php | 5.5.11 | All | All | All |
| Application | Php | Php | 5.5.12 | All | All | All |
| Application | Php | Php | 5.5.13 | All | All | All |
| Application | Php | Php | 5.5.14 | All | All | All |
| Application | Php | Php | 5.5.15 | All | All | All |
| Application | Php | Php | 5.5.16 | All | All | All |
| Application | Php | Php | 5.5.17 | All | All | All |
| Application | Php | Php | 5.5.18 | All | All | All |
| Application | Php | Php | 5.5.19 | All | All | All |
| Application | Php | Php | 5.5.2 | All | All | All |
| Application | Php | Php | 5.5.20 | All | All | All |
| Application | Php | Php | 5.5.21 | All | All | All |
| Application | Php | Php | 5.5.22 | All | All | All |
| Application | Php | Php | 5.5.23 | All | All | All |
| Application | Php | Php | 5.5.24 | All | All | All |
| Application | Php | Php | 5.5.25 | All | All | All |
| Application | Php | Php | 5.5.3 | All | All | All |
| Application | Php | Php | 5.5.4 | All | All | All |
| Application | Php | Php | 5.5.5 | All | All | All |
| Application | Php | Php | 5.5.6 | All | All | All |
| Application | Php | Php | 5.5.7 | All | All | All |
| Application | Php | Php | 5.5.8 | All | All | All |
| Application | Php | Php | 5.5.9 | All | All | All |
| Application | Php | Php | 5.6.0 | All | All | All |
| Application | Php | Php | 5.6.1 | All | All | All |
| Application | Php | Php | 5.6.2 | All | All | All |
| Application | Php | Php | 5.6.3 | All | All | All |
| Application | Php | Php | 5.6.4 | All | All | All |
| Application | Php | Php | 5.6.5 | All | All | All |
| Application | Php | Php | 5.6.6 | All | All | All |
| Application | Php | Php | 5.6.7 | All | All | All |
| Application | Php | Php | 5.6.8 | All | All | All |
| Application | Php | Php | 5.6.9 | All | All | All |
| Application | Php | Php | All | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PHP: Multiple vulnerabilities (GLSA 201606-10) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-3344-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| PHP :: Bug #69667 :: segfault in php_pgsql_meta_data | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | |
| PHP Multiple Bugs Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| 208.43.231.11 Git - php-src.git/commit | af854a3a-2127-422b-91ae-364da2661108 | git.php.net | |
| PHP CVE-2015-4644 Incomplete Fix Null Pointer Deference Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Linux Bulletin - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | php.net | |
| oss-security - Re: PHP 5.6.10 / 5.5.26 / 5.4.42 CVE request | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| 208.43.231.11 Git - php-src.git/commit | MITRE | git.php.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.