PHP session parallelism Arbitrary Code Execution Vulnerability (CVE-2015-6835)
PHP session parallelism Arbitrary Code Execution Vulnerability (CVE-2015-6835)
Release date:
Updated on:
Affected Systems:
PHP <5.4.45
PHP 5.6.x <5.6.13
PHP 5.5.x <5.5.29
Description:
CVE (CAN) ID: CVE-2015-6835
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
In PHP <5.4.45, 5.5.x <5.5.29, 5.6.x <5.6.13, the session parsers handle multiple php_var_unserializ calls by mistake. Remote attackers can cause DoS by constructing session content.
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://php.net/ChangeLog-5.php
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: