CVE-2015-4604
Estado: ModificadaAlta (7.5)—
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.39%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-20
Referencias
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=f938112c495b0d26572435c0be73ac0bfe642ecd
- http://php.net/ChangeLog-5.php
- http://rhn.redhat.com/errata/RHSA-2015-1135.html
- http://rhn.redhat.com/errata/RHSA-2015-1186.html
- http://rhn.redhat.com/errata/RHSA-2015-1187.html
- http://www.openwall.com/lists/oss-security/2015/06/16/12
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/75241
- http://www.securitytracker.com/id/1032709
- https://bugs.php.net/bug.php?id=68819
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=f938112c495b0d26572435c0be73ac0bfe642ecd
- http://php.net/ChangeLog-5.php
- http://rhn.redhat.com/errata/RHSA-2015-1135.html
- http://rhn.redhat.com/errata/RHSA-2015-1186.html
- http://rhn.redhat.com/errata/RHSA-2015-1187.html
- http://www.openwall.com/lists/oss-security/2015/06/16/12
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/75241
- http://www.securitytracker.com/id/1032709
- https://bugs.php.net/bug.php?id=68819
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-4604",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-05-16T10:59:12.237",
"references": [
{
"url": "http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=f938112c495b0d26572435c0be73ac0bfe642ecd",
"source": "secalert@redhat.com"
},
{
"url": "http://php.net/ChangeLog-5.php",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1135.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1186.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1187.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/06/16/12",
"source": "secalert@redhat.com"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/75241",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id/1032709",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.php.net/bug.php?id=68819",
"tags": [
"Exploit"
],
"source": "secalert@redhat.com"
},
{
"url": "http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=f938112c495b0d26572435c0be73ac0bfe642ecd",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://php.net/ChangeLog-5.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1135.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1186.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2015-1187.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/06/16/12",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/75241",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1032709",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.php.net/bug.php?id=68819",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a \"Python script text executable\" rule."
},
{
"lang": "es",
"value": "La función mget en softmagic.c en file 5.x, tal como se utiliza en el componente Fileinfo en PHP en versiones anteriores a 5.4.40, 5.5.x en versiones anteriores a 5.5.24 y 5.6.x en versiones anteriores a 5.6.8, no mantiene correctamente una cierta relación de puntero, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código arbitrario a traves de una cadena manipulada que no es manejada correctamente por una regla \"secuencia de comandos de texto ejecutable de Python\"."
}
],
"lastModified": "2026-06-17T00:27:35.257",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1228E622-0524-4254-BA07-6EED39637EA4",
"versionEndIncluding": "5.4.39"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F6D9B19-E64D-4BED-9194-17460CE19E6F"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F644EA6C-50C6-4A1C-A4AC-287AA9477B46"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DD47F30-74F5-48E8-8657-C2373FE2BD22"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C09527B-6B47-41F8-BDE6-01C47E452286"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E454D87-23CB-4D7F-90FE-942EE54D661F"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1031E646-F2CF-4A3E-8E6A-5D4BC950BEDA"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "130E50C1-D209-4CFF-9399-69D561340FBB"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1F29948-9417-460B-8B04-D91AE4E8B423"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A37D00C1-4F41-4400-9CE4-8E8BAA3E4142"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "093D08B7-CC3C-4616-8697-F15B253A7D9A"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9CD8FEE-DE7B-47CB-9985-4092BFA071D0"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A30B2D9E-F289-43C9-BFBC-1CEF284A417E"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE41CFDF-8ECD-41C1-94A7-5AFD42C5DDEA"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AEAC9BA-AF82-4345-839C-D339DCB962A7"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EFE682F-52E3-48EC-A993-F522FC29712F"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "840EE3AC-5293-4F33-9E2C-96A0A2534B02"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C0FC407-96DB-425E-BB57-7A5BA839C37F"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3839C81-3DAB-4E1D-9D95-BEFFD491F43D"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC63A449-5D92-4F5F-8186-B58FFFBA54FE"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F18236F6-2065-4A6A-93E7-FD90E650C689"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEFBA84A-A4E4-438B-B9B5-8549809DCECC"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "146D3DC9-50F4-430B-B321-68ECE78879A7"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D5A7CA6-7653-46C5-8DF7-95584BF7A879"
},
{
"criteria": "cpe:2.3:a:php:php:5.5.23:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5BA8300-2F4D-4C1E-8CCE-F45E8F3547A0"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE65D0D4-CB56-4946-AB44-2EF554602A96"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1F13E2D-A8F7-4B74-8D03-7905C81672C9"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE18933A-5FE6-41C7-B1B6-DA3E762C3FB6"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AE1289F-03A6-4621-B387-5F5ADAC4AE92"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "383697F5-D29E-475A-84F3-46B54A928889"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "786ED182-5D71-4197-9196-12AB5CF05F85"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF90980D-74AD-44AA-A7C5-A0B294CCE4F8"
},
{
"criteria": "cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48D6B69C-8F27-4F4C-B953-67A7F9C2FBA5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C068A4-3780-4EAB-A937-6082DF847564"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C84489B-B08C-4854-8A12-D01B6E45CF79"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7071F0C7-E43E-4F2E-9FEB-E8FB3DEA4749"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E8CD4EF-DC90-40BB-A721-6EC087507906"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "825ECE2D-E232-46E0-A047-074B34DB1E97"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}