Описание
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | php | Will not fix | ||
Red Hat Enterprise Linux 5 | php53 | Will not fix | ||
Red Hat Enterprise Linux 6 | php | Will not fix | ||
Red Hat Enterprise Linux 7 | php | Will not fix | ||
Red Hat OpenShift Enterprise 2 | php | Will not fix | ||
Red Hat Software Collections | rh-php56-php | Will not fix | ||
Red Hat Software Collections | rh-php71-php | Not affected | ||
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php70-php | Fixed | RHSA-2018:1296 | 03.05.2018 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php70-php | Fixed | RHSA-2018:1296 | 03.05.2018 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php70-php | Fixed | RHSA-2018:1296 | 03.05.2018 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.
In PHP before 5.6.31, an invalid free in the WDDX deserialization of b ...
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.
Уязвимость функции wddx_deserialize() интерпретатора языка программирования PHP , связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании
5.9 Medium
CVSS3