PHP SoapFault ::__ toString method information leakage Vulnerability (CVE-2015-4599)
PHP SoapFault ::__ toString method information leakage Vulnerability (CVE-2015-4599)
Release date:
Updated on:
Affected Systems:
PHP <5.4.40
PHP 5.6.x <5.6.8
PHP 5.5.x <5.5.24
Description:
CVE (CAN) ID: CVE-2015-4599
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
PHP <5.4.40, 5.5.x <5.5.24, 5.6.x <5.6.8, ext/soap. the c/SoapFault ::__ toString method has a security vulnerability. Remote attackers can use certain data types to cause DoS attacks.
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://php.net/ChangeLog-5.php
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: