PHP spl_ptr_heap_insert function re-exploitation vulnerability after release (CVE-2015-4116)
PHP spl_ptr_heap_insert function re-exploitation vulnerability after release (CVE-2015-4116)
Release date:
Updated on:
Affected Systems:
PHP <5.6.11
PHP <5.5.27
Description:
CVE (CAN) ID: CVE-2015-4116
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
In PHP <5.5.27 and <5.6.11, ext/spl/spl_heap.c/spl_ptr_heap_insert has the post-release Reuse Vulnerability. By triggering the failed SplMinHeap: compare operation, remote attackers can execute arbitrary code.
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://php.net/ChangeLog-5.php
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: