VDB
GCVE-110-MAGEIA-2015-134
GCVE-110-MAGEIA-2015-134
Advisory Published
Heap overflow vulnerability in regcomp.c in the ereg extension in PHP before
5.5.23 on 32-bit systems (CVE-2015-2305).
Integer overflow in zip extension in PHP before 5.5.23 leads to writing past
heap boundary (CVE-2015-2331).
Use after free vulnerability in unserialize() in PHP before 5.5.23
(CVE-2015-2787).
PHP has been updated to version 5.5.23, which fixes these issues and other
bugs. The php zip extension uses the libzip library, so it has been patched
to fix CVE-2015-2331.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | libzip | 0 (affected), 0.11.2-1.1.mga4 (unaffected), 0.11.2-1.1.mga4 (unaffected), 0 (affected) | — |
| Mageia | java-1.8.0-openjdk | 0 (affected), 1.8.0.60-1.b27.1.mga5 (unaffected) | — |
| Mageia | php | 0 (affected), 5.5.23-1.mga4 (unaffected), 0 (affected), 5.5.23-1.mga4 (unaffected) | — |
| Mageia | timezone | 0 (affected), 2015f-1.mga5 (unaffected) | — |
| Mageia | icedtea-web | 1.6.1-1.mga5 (unaffected), 0 (affected) | — |
| Mageia | php-apc | 3.1.15-4.13.mga4 (unaffected), 0 (affected), 3.1.15-4.13.mga4 (unaffected), 0 (affected) | — |
Aliases
References
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.