CVE-2016-7411
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that references a partially constructed object.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.65% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- php/php
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/09/15/10Mailing List
- http://www.php.net/ChangeLog-5.phpRelease Notes
- http://www.securityfocus.com/bid/93009
- http://www.securitytracker.com/id/1036836
- https://bugs.php.net/bug.php?id=73052Exploit, Issue Tracking
- https://github.com/php/php-src/commit/6a7cc8ff85827fa9ac715b3a83c2d9147f33cd43?w=1Issue Tracking, Patch
- https://security.gentoo.org/glsa/201611-22
- http://www.openwall.com/lists/oss-security/2016/09/15/10Mailing List
- http://www.php.net/ChangeLog-5.phpRelease Notes
- http://www.securityfocus.com/bid/93009
- http://www.securitytracker.com/id/1036836
- https://bugs.php.net/bug.php?id=73052Exploit, Issue Tracking
- https://github.com/php/php-src/commit/6a7cc8ff85827fa9ac715b3a83c2d9147f33cd43?w=1Issue Tracking, Patch
- https://security.gentoo.org/glsa/201611-22
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.