Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

PHP 5.5.x < 5.5.30 / 5.6.x < 5.6.14 Multiple Vulnerabilities

High

Synopsis

The remote web server uses a version of PHP that is affected by multiple vulnerabilities.

Description

Versions of PHP 5.5.x prior to 5.5.30, or 5.6.x prior to 5.6.14 are vulnerable to the following issues :

- A NULL pointer dereference flaw affects the phar_get_fp_offset() function in 'ext/phar/util.c' that is triggered when pointing to a non-existent file. This may allow a remote attacker to cause a denial of service. (OSVDB 128347) - An uninitialized pointer flaw affects the phar_make_dirstream() function in 'lext/phar/dirstream.c' that is triggered when handling a zip entry filename that is '/', which can result in a crash or potentially a data leak. (OSVDB 128348)

Solution

Upgrade to PHP version 5.6.14, or later. If 5.6.x cannot be obtained, 5.5.30 is also patched for these vulnerabilities.