CVE-2015-1352: Apple Mac OS X

Medium severity, CVSS 5.0. EPSS: 7.4% chance of exploitation in the next 30 days.

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

Affected products

  • Apple Mac OS X: up to and including 10.10.5
  • PHP PHP: before 5.4.40 (fixed in 5.4.40); from 5.5.0, before 5.5.24 (fixed in 5.5.24); from 5.6.0, before 5.6.8 (fixed in 5.6.8)

Published 2015-03-30. Last modified 2026-06-17.