Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3622

Опубликовано: 19 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 9.8

Описание

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

РелизСтатусПримечание
devel

not-affected

5.5.12+dfsg-2ubuntu4
esm-infra-legacy/trusty

not-affected

lucid

not-affected

precise

not-affected

trusty

not-affected

trusty/esm

not-affected

upstream

released

5.6.1+dfsg-1

Показывать по

EPSS

Процентиль: 83%
0.01951
Низкий

6.8 Medium

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

CVSS3: 9.8
nvd
больше 5 лет назад

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

CVSS3: 9.8
debian
больше 5 лет назад

Use-after-free vulnerability in the add_post_var function in the Posth ...

github
около 3 лет назад

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость функции add_post_var интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный PHP-код

EPSS

Процентиль: 83%
0.01951
Низкий

6.8 Medium

CVSS2

9.8 Critical

CVSS3