Your submission was sent successfully! Close

CVE-2016-5771

Published: 24 June 2016

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.

Priority

Low

CVSS 3 base score: 9.8

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr)
Released (5.5.9+dfsg-1ubuntu4.19)
Patches:
Upstream: http://git.php.net/?p=php-src.git;a=commit;h=3f627e580acfdaf0595ae3b115b8bec677f203ee
php7.0
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Notes

AuthorNote
seth-arnold
Applications should never deserialize unauthenticated data.
mdeslaur
does not affect 7.0.x
precise needs backported fix
we will not be fixing this in Ubuntu 12.04 LTS. We recommend
validating untrusted data before unserializing.

References

Bugs