Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-6834

Опубликовано: 16 мая 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

РелизСтатусПримечание
devel

released

5.6.11+dfsg-1ubuntu3
esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.13
precise

released

5.3.10-1ubuntu3.20
trusty

released

5.5.9+dfsg-1ubuntu4.13
trusty/esm

released

5.5.9+dfsg-1ubuntu4.13
upstream

released

5.5.29,5.6.13
vivid

released

5.6.4+dfsg-4ubuntu6.3

Показывать по

EPSS

Процентиль: 97%
0.4205
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

CVSS3: 9.8
nvd
больше 9 лет назад

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

CVSS3: 9.8
debian
больше 9 лет назад

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x be ...

CVSS3: 9.8
github
больше 3 лет назад

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

fstec
больше 9 лет назад

Уязвимости интерпретатора PHP, позволяющие нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.4205
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3