vulnerability

Huawei EulerOS: CVE-2016-7480: php security update

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
2017-01-11
Added
2019-12-18
Modified
2024-11-27

Description

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

Solution(s)

huawei-euleros-2_0_sp3-upgrade-phphuawei-euleros-2_0_sp3-upgrade-php-clihuawei-euleros-2_0_sp3-upgrade-php-commonhuawei-euleros-2_0_sp3-upgrade-php-gdhuawei-euleros-2_0_sp3-upgrade-php-ldaphuawei-euleros-2_0_sp3-upgrade-php-mysqlhuawei-euleros-2_0_sp3-upgrade-php-odbchuawei-euleros-2_0_sp3-upgrade-php-pdohuawei-euleros-2_0_sp3-upgrade-php-pgsqlhuawei-euleros-2_0_sp3-upgrade-php-processhuawei-euleros-2_0_sp3-upgrade-php-recodehuawei-euleros-2_0_sp3-upgrade-php-soaphuawei-euleros-2_0_sp3-upgrade-php-xmlhuawei-euleros-2_0_sp3-upgrade-php-xmlrpc
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.