CVE-2015-4605: PHP

High severity, CVSS 7.5. EPSS: 7.4% chance of exploitation in the next 30 days.

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

Affected products

  • PHP PHP: up to and including 5.4.39; version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; …
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Eus: version 7.1 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Eus: version 7.1 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2016-05-16. Last modified 2026-06-17.