USN-2391-1: php5 vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | October 29, 2014 | October 31, 2014 | July 04, 2017 |
Description
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.
Free Nexpose Download
Discover, prioritize, and remediate security risks today!
References
Solution
ubuntu-upgrade-libapache2-mod-php5Related Vulnerabilities
- Oracle Solaris 11: CVE-2014-3669: Vulnerability in PHP
- RHSA-2014:1765: php54-php security update
- Amazon Linux AMI: Security patch for php55 (ALAS-2014-435) (multiple CVEs)
- OS X update for Admin Framework (CVE-2014-3668)
- DSA-3072-1 file -- security update
- Amazon Linux AMI: Security patch for file (ALAS-2014-453) (CVE-2014-3710)
- RHSA-2014:1824: php security update
- Amazon Linux AMI: Security patch for php54 (ALAS-2014-450) (CVE-2014-3710)
- OS X update for PHP (CVE-2014-3669)
- OS X update for Admin Framework (CVE-2014-3669)
- DSA-3064-1 php5 -- security update
- RHSA-2016:0760: file security, bug fix, and enhancement update
- ELSA-2015-2155 Moderate: Oracle Linux file security and bug fix update
- Oracle Solaris 11: CVE-2014-3668: Vulnerability in PHP
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 5
- Cent OS: CVE-2014-3668: CESA-2014:1768 (php53)
- Cent OS: CVE-2014-3670: CESA-2014:1824 (php)
- RHSA-2015:0021: php security update
- Gentoo Linux: CVE-2014-3668: PHP: Multiple vulnerabilities
- OS X update for PHP (CVE-2014-3670)
- DSA-3074-1 php5 -- security update
- Gentoo Linux: CVE-2014-3669: PHP: Multiple vulnerabilities
- FreeBSD: file -- multiple vulnerabilities (FreeBSD-SA-14:28.file) (Multiple CVEs)
- ELSA-2014-1824 Important: Oracle Linux php security update
- Gentoo Linux: CVE-2014-3670: PHP: Multiple vulnerabilities
- ELSA-2014-1768 Important: Oracle Linux php53 security update
- Amazon Linux AMI: Security patch for php54 (ALAS-2014-434) (multiple CVEs)
- Oracle Solaris 11: CVE-2014-3670: Vulnerability in PHP
- Amazon Linux AMI: Security patch for php55 (ALAS-2014-451) (CVE-2014-3710)
- OS X update for PHP (CVE-2014-3710)
- RHSA-2015:2155: file security and bug fix update
- PHP Vulnerability: CVE-2014-3670
- OS X update for PHP (CVE-2014-3668)
- RHSA-2014:1766: php55-php security update
- USN-2494-1: file vulnerabilities
- RHSA-2014:1768: php53 security update
- OS X update for Admin Framework (CVE-2014-3670)
- SUSE: CVE-2014-3668: SUSE Linux Security Advisory
- PHP Vulnerability: CVE-2014-3710
- RHSA-2014:1767: php security update
- ELSA-2015-1135 Important: Oracle Linux php security and bug fix update
- Oracle Solaris 11: CVE-2014-3710: Vulnerability in PHP
- OS X update for Admin Framework (CVE-2014-3710)
- PHP Vulnerability: CVE-2014-3668
- PHP Vulnerability: CVE-2014-3669
- ELSA-2014-1767 Important: Oracle Linux php security update
- Gentoo Linux: CVE-2014-3710: file: Multiple vulnerabilities
- SUSE: CVE-2014-3670: SUSE Linux Security Advisory