vulnerability
FreeBSD: VID-85eb4e46-cf16-11e5-840f-485d605f4717 (CVE-2016-2554): php -- multiple vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Feb 9, 2016 | Dec 10, 2025 | Dec 10, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 9, 2016
Added
Dec 10, 2025
Modified
Dec 10, 2025
Description
PHP reports: Core: Fixed bug #71039 (exec functions ignore length but look for NULL termination). Fixed bug #71323 (Output of stream_get_meta_data can be falsified by its input). Fixed bug #71459 (Integer overflow in iptcembed()). PCRE: Upgraded bundled PCRE library to 8.38.(CVE-2015-8383, CVE-2015-8386, CVE-2015-8387, CVE-2015-8389, CVE-2015-8390, CVE-2015-8391, CVE-2015-8393, CVE-2015-8394) Phar: Fixed bug #71354 (Heap corruption in tar/zip/phar parser). Fixed bug #71391 (NULL Pointer Dereference in phar_tar_setupmetadata()). Fixed bug #71488 (Stack overflow when decompressing tar archives). (CVE-2016-2554) WDDX: Fixed bug #71335 (Type Confusion in WDDX Packet Deserialization).
Solutions
freebsd-upgrade-package-php55freebsd-upgrade-package-php55-pharfreebsd-upgrade-package-php55-wddxfreebsd-upgrade-package-php56freebsd-upgrade-package-php56-pharfreebsd-upgrade-package-php56-wddx
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.