Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-6836

Опубликовано: 19 янв. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 7.3

Описание

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

РелизСтатусПримечание
devel

released

5.6.11+dfsg-1ubuntu3
esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.13
precise

released

5.3.10-1ubuntu3.20
trusty

released

5.5.9+dfsg-1ubuntu4.13
trusty/esm

released

5.5.9+dfsg-1ubuntu4.13
upstream

released

5.5.29,5.6.13
vivid

released

5.6.4+dfsg-4ubuntu6.3

Показывать по

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

redhat
почти 10 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

CVSS3: 7.3
nvd
больше 9 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

CVSS3: 7.3
debian
больше 9 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, ...

CVSS3: 7.3
github
больше 3 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

fstec
больше 9 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS2

7.3 High

CVSS3