Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6288

Опубликовано: 25 июл. 2016
Источник: debian
EPSS Низкий

Описание

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hhvmfixed3.12.1+dfsg-1package
php5fixed5.6.15+dfsg-1package

Примечания

  • https://bugs.php.net/bug.php?id=70480

  • https://github.com/facebook/hhvm/commit/3fa7e73055855c409d48e8aa1dc416a76d3dd764

  • https://git.php.net/?p=php-src.git;a=commitdiff;h=629e4da7cc8b174acdeab84969cbfc606a019b31

EPSS

Процентиль: 92%
0.08397
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 6.2
redhat
почти 10 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
nvd
около 9 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 9.8
github
больше 3 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

suse-cvrf
почти 9 лет назад

Security update for php53

EPSS

Процентиль: 92%
0.08397
Низкий