Lucene search

K
f5F5F5:K30363030
HistoryDec 22, 2016 - 12:00 a.m.

K30363030 : PHP vulnerability CVE-2016-5771

2016-12-2200:00:00
my.f5.com
29

8.6 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.4%

Security Advisory Description

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data. (CVE-2016-5771)
Impact
BIG-IP and BIG-IQ
The vulnerable code exists and may be exposed through customer customization. However, these systems are not vulnerable in the default, standard, or recommended configuration.
Enterprise Manager
The vulnerability can allow unauthorized disclosure of information, unauthorized modification, or disruption of service.
F5 WebSafe Alert Server
The impact is currently unknown. F5 is still researching the issue and will update this article when the information has been confirmed. F5 Technical Support has no additional information about this issue.