CVE-2015-4643: Debian Linux
Critical severity, CVSS 9.8. EPSS: 16.3% chance of exploitation in the next 30 days.
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Oracle Linux: version 6 only; version 7 only
- PHP PHP: before 5.4.42 (fixed in 5.4.42); from 5.5.0, before 5.5.26 (fixed in 5.5.26); from 5.6.0, before 5.6.10 (fixed in 5.6.10)
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 6.6 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
- Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.3 only; version 7.6 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2016-05-16. Last modified 2026-06-17.