PT-2016-2109 · Php · Php

Published

2016-05-21

·

Updated

2019-02-14

·

CVE-2015-8878

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.28 PHP versions 5.6.x prior to 5.6.12
Description The issue is caused by errors in synchronization when using a shared resource in the main/php open temporary file.c function of the PHP interpreter. This allows remote attackers to cause a denial of service by exploiting a race condition and heap memory corruption, leveraging an application that performs many temporary-file accesses.
Recommendations For PHP versions prior to 5.5.28, update to version 5.5.28 or later. For PHP versions 5.6.x prior to 5.6.12, update to version 5.6.12 or later.

Fix

DoS

Race Condition

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01461
CVE-2015-8878
DLA-499-1

Affected Products

Php