Bug 1256322 (CVE-2015-6832) - CVE-2015-6832 php: dangling pointer in the unserialization of ArrayObject items
Summary: CVE-2015-6832 php: dangling pointer in the unserialization of ArrayObject items
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2015-6832
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: Engineering1305854 Engineering1305855
Blocks: Embargoed1252058 Embargoed1306180
TreeView+ depends on / blocked
 
Reported: 2015-08-24 11:13 UTC by Vasyl Kaigorodov
Modified: 2019-10-10 10:06 UTC (History)
17 users (show)

Fixed In Version: PHP 5.6.12, PHP 5.5.28, PHP 5.4.44
Doc Type: Bug Fix
Doc Text:
A flaw was discovered in the way PHP performed object unserialization. Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code.
Clone Of:
Environment:
Last Closed: 2015-10-27 10:01:30 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0457 0 normal SHIPPED_LIVE Moderate: rh-php56-php security update 2016-03-16 00:55:18 UTC

Description Vasyl Kaigorodov 2015-08-24 11:13:02 UTC
A vulnerability in SPL module, that can potentially lead to code execution, was reported in PHP:
https://bugs.php.net/bug.php?id=70068

CVE assignment: http://seclists.org/oss-sec/2015/q3/523
Upstream fix: http://git.php.net/?p=php-src.git;a=commit;h=b7fa67742cd8d2b0ca0c0273b157f6ffee9ad6e2

Comment 3 errata-xmlrpc 2016-03-15 20:57:09 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6

Via RHSA-2016:0457 https://rhn.redhat.com/errata/RHSA-2016-0457.html


Note You need to log in before you can comment on or make changes to this bug.