Lucene search

K
f5F5F5:K35240323
HistoryMay 23, 2016 - 12:00 a.m.

K35240323 : PHP vulnerability CVE-2016-4539

2016-05-2300:00:00
my.f5.com
22

AI Score

8

Confidence

Low

EPSS

0.028

Percentile

90.6%

Security Advisory Description

The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other impact via crafted XML data in the second argument, leading to a parser level of zero. (CVE-2016-4539)
Impact
In default configurations, F5 products are not vulnerable. Versions listed as vulnerable include vulnerable code, but the code is not used in standard configurations.