Lucene search

K
f5F5F5:K29691966
HistoryDec 22, 2016 - 12:00 a.m.

K29691966 : PHP vulnerability CVE-2016-5773

2016-12-2200:00:00
my.f5.com
67

8.4 High

AI Score

Confidence

Low

0.063 Low

EPSS

Percentile

93.7%

Security Advisory Description

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object. (CVE-2016-5773)

Impact

BIG-IP, BIG-IQ, F5 iWorkflow, Enterprise Manager, ARX, LineRate, Traffix SDC

None

F5 WebSafe Alert Server

The impact is currently unknown. F5 is still researching the issue and will update this article when the information has been confirmed. F5 Technical Support has no additional information about this issue.