Skip to main content

PHP Remote Code Execution Vulnerability

Last Update Date: 27 Mar 2015 12:47 Release Date: 27 Mar 2015 3122 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was identified in PHP. A remote user can cause arbitrary code to be executed on the target system.

 

A remote user can create a specially crafted ZIP archive file that, when loaded by the target application, will trigger an integer overflow and potentially execute arbitrary code on the target system. The code will run with the privileges of the target application.


Impact

  • Remote Code Execution

System / Technologies affected

  • Prior to versions 5.4.39, 5.5.23, 5.6.7

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (5.4.39, 5.5.23, 5.6.7).

Vulnerability Identifier


Source


Related Link