PHP ext/snmp. c DoS Vulnerability (CVE-2016-6295)
PHP ext/snmp. c DoS Vulnerability (CVE-2016-6295)
Release date:
Updated on:
Affected Systems:
PHP <5.5.38
PHP 7.x <7.0.9
PHP 5.6.x <5.6.24
Description:
CVE (CAN) ID: CVE-2016-6295
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
PHP <5.5.38, 5.6.x <5.6.24, 7.x <7.0.9, ext/snmp. c does not properly process deserialization and garbage collection. By constructing serialized data, remote attackers can cause denial of service (reuse and application crash upon release ).
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.php.net /? P = php-src.git; a = commit; h = cab1c3b3708eead315e033359d07049b23b147a3
Https://bugs.php.net/72479
Http://php.net/ChangeLog-5.php
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: