Intrusion Prevention

PHP.Phar.Parse.Tarfile.Integer.Overflow

Description

This indicates an attack attempt to exploit an Integer Overflow vulnerability in PHP.
The vulnerability is due to a numeric error in the application when handling malicious requests. A remote attacker may be able exploit this to gain unauthorized access to the sensitive information in the affected machine via crafted requests.

Affected Products

PHP Group PHP 5.4.x prior to 5.4.41
PHP Group PHP 5.5.x prior to 5.5.25
PHP Group PHP 5.6.x prior to 5.6.9

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://php.net/ChangeLog-5.php#5.6.9

CVE References

CVE-2015-4021