Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-6835

Опубликовано: 16 мая 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

РелизСтатусПримечание
devel

released

5.6.11+dfsg-1ubuntu3
esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.13
precise

released

5.3.10-1ubuntu3.20
trusty

released

5.5.9+dfsg-1ubuntu4.13
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.13
upstream

released

5.5.29,5.6.13
vivid

released

5.6.4+dfsg-4ubuntu6.3

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

CVSS3: 9.8
nvd
больше 9 лет назад

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

CVSS3: 9.8
debian
больше 9 лет назад

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, an ...

CVSS3: 9.8
github
больше 3 лет назад

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

fstec
больше 9 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

7.5 High

CVSS2

9.8 Critical

CVSS3