PT-2014-2045 · Php+4 · Php+4

Published

2014-07-18

·

Updated

2024-06-15

·

CVE-2014-3669

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.34 PHP versions 5.5.x prior to 5.5.18 PHP versions 5.6.x prior to 5.6.2
Description The issue is related to errors in number processing in the object custom function of the PHP interpreter. It may allow a remote attacker to cause a denial of service or possibly execute arbitrary code by providing an argument to the unserialize function that triggers the calculation of a large length value.
Recommendations For PHP versions prior to 5.4.34, update to version 5.4.34 or later. For PHP versions 5.5.x prior to 5.5.18, update to version 5.5.18 or later. For PHP versions 5.6.x prior to 5.6.2, update to version 5.6.2 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02651
CESA-2014_1767
CVE-2014-3669
DLA-94-1
DSA-3064-1
MGASA-2014-0430
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014:1767
RHSA-2014:1768
RHSA-2014:1824
RHSA-2014_1767
RHSA-2014_1768
RHSA-2014_1824
RHSA-2015:0021
SUSE-SU-2016:1638-1
USN-2391-1

Affected Products

Centos
Php
Red Hat
Suse
Ubuntu