PHP Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Servers - Web Servers
Multiple vulnerabilities were identified in PHP. A remote user can execute arbitrary code on the target system and cause denial of service conditions.
A user can create a specially crafted PHP file that will trigger a use-after-free memory error in the PHP unserialize() function to potentially execute arbitrary code.
A user can create a specially crafted PHP file that will trigger an out-of-bounds memory read and crash.
A user can create a JPEG file with a specially crafted EXIF tag that, when processed by the PHP application, will free an uninitialized pointer and potentially execute arbitrary code.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Versions prior to 5.4.37, 5.5.21, 5.6.5
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (5.4.37, 5.5.21, 5.6.5).
Vulnerability Identifier
Source
Related Link
Share with