The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-php | Aug 30, 2017 | Jan 19, 2016 |
| Apple Osx Apachemodphp | apple-osx-security-update-2015-004-yosemiteapple-osx-security-update-2015-007-mavericksapple-osx-upgrade-latest | Mar 29, 2016 | Jan 19, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-lang-php | Oct 30, 2017 | Jan 19, 2016 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | Jan 19, 2016 | |
| Php | php-upgrade-5_4_45php-upgrade-5_5_29php-upgrade-5_6_13 | Feb 1, 2016 | Jan 19, 2016 | |
| Ubuntu | ubuntu-upgrade-libapache2-mod-php5ubuntu-upgrade-php5-cgiubuntu-upgrade-php5-cliubuntu-upgrade-php5-fpm | Nov 8, 2024 | Jan 19, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub