7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
9.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
0.094 Low
EPSS
Percentile
94.8%
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before
7.0.13, allows remote attackers to cause a denial of service (infinite
loop) via a crafted Exception object in serialized data, a related issue to
CVE-2015-8876.
Author | Note |
---|---|
mdeslaur | can’t reproduce with 7.0.13, assumed fixed php5 needs CVE-2016-9137 to be applied |
blog.checkpoint.com/2016/12/27/check-point-discovers-three-zero-day-vulnerabilities-web-programming-language-php-7
blog.checkpoint.com/wp-content/uploads/2016/12/PHP_Technical_Report.pdf
launchpad.net/bugs/cve/CVE-2016-7478
nvd.nist.gov/vuln/detail/CVE-2016-7478
security-tracker.debian.org/tracker/CVE-2016-7478
ubuntu.com/security/notices/USN-3196-1
www.cve.org/CVERecord?id=CVE-2016-7478
www.youtube.com/watch?v=LDcaPstAuPk
7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
9.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
0.094 Low
EPSS
Percentile
94.8%