PT-2016-3385 · Php+2 · Php+2

Fernando

·

Publicado

2016-09-11

·

Atualizado

2020-11-16

·

CVE-2016-7131

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.25 PHP versions 7.x prior to 7.0.10
Description The issue is related to errors in handling a malformed wddxPacket XML document in the wddx deserialize call, potentially leading to a denial of service or other unspecified impacts. This can be caused by a tag that lacks a < character. The vulnerability is associated with pointer dereference errors, which can be exploited by a remote attacker via a malformed XML document.
Recommendations For PHP versions prior to 5.6.25, update to version 5.6.25 or later. For PHP versions 7.x prior to 7.0.10, update to version 7.0.10 or later.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02416
CVE-2016-7131
DLA-749-1
DSA-3689-1
OPENSUSE-SU-2016_2337-1
OPENSUSE-SU-2016_2451-1
RHSA-2016:2750
SUSE-SU-2016:2328-1
SUSE-SU-2016:2408-1
SUSE-SU-2016:2459-1
SUSE-SU-2016:2460-1
SUSE-SU-2016:2460-2
USN-3095-1

Produtos afetados

Php
Suse
Ubuntu