Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4116

Опубликовано: 16 мая 2016
Источник: debian
EPSS Низкий

Описание

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.6.11+dfsg-1package
php5fixed5.6.12+dfsg-0+deb8u1jessiepackage

Примечания

  • https://bugs.php.net/bug.php?id=69737

  • Fixed in 5.6.11, 5.5.27

  • Not treated as security issue, only triggerable with malformed PHP code

EPSS

Процентиль: 88%
0.04153
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

redhat
около 10 лет назад

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

CVSS3: 9.8
nvd
больше 9 лет назад

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

CVSS3: 9.8
github
больше 3 лет назад

Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.

fstec
больше 9 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 88%
0.04153
Низкий