PT-2015-1021 · Php+5 · Php+5

Vasyl Kaigorodov

·

Publicado

2015-02-23

·

Atualizado

2024-06-15

·

CVE-2015-0273

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.38 PHP versions 5.5.x prior to 5.5.22 PHP versions 5.6.x prior to 5.6.6
Description The issue allows remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php date timezone initialize from hash function or (b) DateTime data handled by the php date initialize from hash function. This is due to multiple use-after-free vulnerabilities in the ext/date/php date.c component of PHP.
Recommendations For PHP versions prior to 5.4.38, update to version 5.4.38 or later. For PHP versions 5.5.x prior to 5.5.22, update to version 5.5.22 or later. For PHP versions 5.6.x prior to 5.6.6, update to version 5.6.6 or later. As a temporary workaround, consider restricting the use of the php date timezone initialize from hash and php date initialize from hash functions until a patch is available. Avoid using crafted serialized input containing R or r type specifiers in DateTimeZone and DateTime data.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09850
CESA-2015_1135
CESA-2015_1218
CVE-2015-0273
DSA-3195-1
HPSBUX03337
MGASA-2015-0090
OPENSUSE-SU-2015_0440-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2015:1053
RHSA-2015:1066
RHSA-2015:1135
RHSA-2015:1218
RHSA-2015_1135
RHSA-2015_1218
SUSE-SU-2015:0424-1
SUSE-SU-2016:1638-1
USN-2535-1

Produtos afetados

Centos
Hp-Ux
Php
Red Hat
Suse
Ubuntu