VDB

GCVE-110-MAGEIA-2015-134

GCVE-110-MAGEIA-2015-134
Advisory Published
Vulnetix · Advisory published April 4, 2015
Heap overflow vulnerability in regcomp.c in the ereg extension in PHP before 5.5.23 on 32-bit systems (CVE-2015-2305). Integer overflow in zip extension in PHP before 5.5.23 leads to writing past heap boundary (CVE-2015-2331). Use after free vulnerability in unserialize() in PHP before 5.5.23 (CVE-2015-2787). PHP has been updated to version 5.5.23, which fixes these issues and other bugs. The php zip extension uses the libzip library, so it has been patched to fix CVE-2015-2331.

Affected Products

VendorProductVersionsPlatforms
Mageialibzip0 (affected), 0.11.2-1.1.mga4 (unaffected), 0.11.2-1.1.mga4 (unaffected), 0 (affected)
Mageiajava-1.8.0-openjdk0 (affected), 1.8.0.60-1.b27.1.mga5 (unaffected)
Mageiaphp0 (affected), 5.5.23-1.mga4 (unaffected), 0 (affected), 5.5.23-1.mga4 (unaffected)
Mageiatimezone0 (affected), 2015f-1.mga5 (unaffected)
Mageiaicedtea-web1.6.1-1.mga5 (unaffected), 0 (affected)
Mageiaphp-apc3.1.15-4.13.mga4 (unaffected), 0 (affected), 3.1.15-4.13.mga4 (unaffected), 0 (affected)

Browse GCVE Records

74,132 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›