Kaspersky ID:
KLA10514
Дата обнаружения:
30/03/2015
Обновлено:
03/06/2020

Описание

Multiple serious vulnerabilities have been found in PHP. Malicious users can exploit these vulnerabilities to inject or execute arbitrary code, bypass security restrictions or cause denial of service.

Below is a complete list of vulnerabilities

  1. Multiple use-after-free vulnerabilities can be exploited remotely via a specially designed call and input and vectors related to Phar archives renaming and;
  2. Improper pathname truncation can be exploited remotely via a specailly designed arguments;
  3. Integer overflow vulnerability can be exploited remotely via a specially designed ZIP archive;
  4. An unknown vulnerability can be exploited remotely via a specially designed GIF image or ELF file;
  5. Heap-based buffer overflow can be exploited remotely via vectors related to dictionaries;
  6. Improper string-length handling can be exploited remotely via a specially designed files.

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2015-2787
    critical
  • CVE-2015-2348
    critical
  • CVE-2015-2331
    critical
  • CVE-2015-2301
    critical
  • CVE-2015-1351
    critical
  • CVE-2015-0273
    critical
  • CVE-2014-9709
    critical
  • CVE-2014-9705
    critical
  • CVE-2014-9653
    critical
  • CVE-2014-9652
    critical

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Confirm changes?
Your message has been sent successfully.