Lucene search

K
f5F5F5:K04127310
HistoryMar 29, 2016 - 12:00 a.m.

K04127310 : PHP vulnerabilities CVE-2016-3141 and CVE-2016-3142

2016-03-2900:00:00
my.f5.com
20

8.2 High

AI Score

Confidence

Low

0.114 Low

EPSS

Percentile

95.2%

Security Advisory Description

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.
Impact
None. F5 products are not affected by this vulnerability.

8.2 High

AI Score

Confidence

Low

0.114 Low

EPSS

Percentile

95.2%