Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5773

Опубликовано: 07 авг. 2016
Источник: debian
EPSS Средний

Описание

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.8-1package
php5fixed5.6.23+dfsg-1package

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=72434

  • https://git.php.net/?p=php-src.git;a=commitdiff;h=f6aef68089221c5ea047d4a74224ee3deead99a6

  • Fixed in 5.5.37, 5.6.23, 7.0.8

EPSS

Процентиль: 94%
0.13358
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 5.6
redhat
почти 9 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
nvd
почти 9 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
github
около 3 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
fstec
почти 9 лет назад

Уязвимость компонента php_zip.c интерпретатора языка программирования PHP , позволяющая нарушителю выполнить произвольный PHP-код или вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.13358
Средний