Skip to main content

PHP Multiple Vulnerabilities

Last Update Date: 27 Jan 2015 09:32 Release Date: 27 Jan 2015 3238 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities were identified in PHP. A remote user can execute arbitrary code on the target system and cause denial of service conditions.

A user can create a specially crafted PHP file that will trigger a use-after-free memory error in the PHP unserialize() function to potentially execute arbitrary code.

A user can create a specially crafted PHP file that will trigger an out-of-bounds memory read and crash.

A user can create a JPEG file with a specially crafted EXIF tag that, when processed by the PHP application, will free an uninitialized pointer and potentially execute arbitrary code.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Versions prior to 5.4.37, 5.5.21, 5.6.5

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (5.4.37, 5.5.21, 5.6.5).

Vulnerability Identifier


Source


Related Link