Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2016-3185
HistoryMay 16, 2016 - 10:59 a.m.

CVE-2016-3185

2016-05-1610:59:00
Debian Security Bug Tracker
security-tracker.debian.org
11

0.007 Low

EPSS

Percentile

79.6%

The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.

OSVersionArchitecturePackageVersionFilename
Debian9allphp7.0< 7.0.33-0+deb9u8php7.0_7.0.33-0+deb9u8_all.deb

0.007 Low

EPSS

Percentile

79.6%