PublicDateAtUSN: 2015-06-09 Candidate: CVE-2015-4147 PublicDate: 2015-06-09 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4147 http://www.openwall.com/lists/oss-security/2015/03/20/14 https://ubuntu.com/security/notices/USN-2658-1 Description: The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a "type confusion" issue. Ubuntu-Description: Notes: mdeslaur> regression fixed in 5.4.40,5.5.24,5.6.8 Bugs: https://bugs.php.net/bug.php?id=69085 https://bugs.php.net/bug.php?id=69293 (regression) Priority: medium Discovered-by: Andrea Palazzo Assigned-to: mdeslaur CVSS: Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commit;h=d5248f67b58ac3107fec82c5b937fc3f4c89784a (5.4-5.6) upstream: http://git.php.net/?p=php-src.git;a=commit;h=0c136a2abd49298b66acb0cad504f0f972f5bfe8 (5.4-5.6) upstream: http://git.php.net/?p=php-src.git;a=commit;h=c8eaca013a3922e8383def6158ece2b63f6ec483 (5.4-5.6) upstream: http://git.php.net/?p=php-src.git;a=commit;h=75f40ae1f3a7ca837d230f099627d121f9b3a32f (5.4-5.6) upstream: http://git.php.net/?p=php-src.git;a=commit;h=ff70b40dc978f3f4c457f72a71bb43fd17ee360b (5.4-5.6) upstream_php5: released (5.4.39,5.5.23,5.6.7) precise_php5: released (5.3.10-1ubuntu3.19) trusty_php5: released (5.5.9+dfsg-1ubuntu4.11) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.11) utopic_php5: released (5.5.12+dfsg-2ubuntu4.6) vivid_php5: released (5.6.4+dfsg-4ubuntu6.2) devel_php5: released (5.6.9+dfsg-1ubuntu1)