Lucene search

K
freebsdFreeBSD3D675519-5654-11E5-9AD8-14DAE9D210B8
HistorySep 03, 2015 - 12:00 a.m.

php -- multiple vulnerabilities

2015-09-0300:00:00
vuxml.freebsd.org
32

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.201 Low

EPSS

Percentile

96.4%

PHP reports:

Core:

Fixed bug #70172 (Use After Free Vulnerability in unserialize()).
Fixed bug #70219 (Use after free vulnerability in session deserializer).

EXIF:

Fixed bug #70385 (Buffer over-read in exif_read_data with TIFF IFD tag byte value of 32 bytes).

hash:

Fixed bug #70312 (HAVAL gives wrong hashes in specific cases).

PCRE:

Fixed bug #70345 (Multiple vulnerabilities related to PCRE functions).

SOAP:

Fixed bug #70388 (SOAP serialize_function_call() type confusion / RCE).

SPL:

Fixed bug #70365 (Use-after-free vulnerability in unserialize() with SplObjectStorage).
Fixed bug #70366 (Use-after-free vulnerability in unserialize() with SplDoublyLinkedList).

XSLT:

Fixed bug #69782 (NULL pointer dereference).

ZIP:

Fixed bug #70350 (ZipArchive::extractTo allows for directory traversal when creating directories).

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.201 Low

EPSS

Percentile

96.4%