PublicDateAtUSN: 2015-12-31 Candidate: CVE-2015-8835 PublicDate: 2016-05-16 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8835 https://ubuntu.com/security/notices/USN-2952-1 Description: The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not properly retrieve keys, which allows remote attackers to cause a denial of service (NULL pointer dereference, type confusion, and application crash) or possibly execute arbitrary code via crafted serialized data representing a numerically indexed _cookies array, related to the SoapClient::__call method in ext/soap/soap.c. Ubuntu-Description: Notes: sbeattie> upstream fixed in 5.6.12, 5.5.28, and 5.4.44 mdeslaur> This CVE is for the first part of the fix, and the first part mdeslaur> listed in the bug. mdeslaur> See CVE-2016-3185 for the second part. Bugs: https://bugs.php.net/bug.php?id=70081 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_php5: upstream: https://git.php.net/?p=php-src.git;a=commitdiff;h=c96d08b27226193dd51f2b50e84272235c6aaa69 upstream_php5: released (5.6.12+dfsg-1) precise_php5: released (5.3.10-1ubuntu3.22) trusty_php5: released (5.5.9+dfsg-1ubuntu4.16) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.16) vivid/stable-phone-overlay_php5: DNE vivid/ubuntu-core_php5: DNE wily_php5: released (5.6.11+dfsg-1ubuntu3.2) devel_php5: DNE Patches_php7.0: upstream_php7.0: released (7.0.0) precise_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/stable-phone-overlay_php7.0: DNE vivid/ubuntu-core_php7.0: DNE wily_php7.0: DNE devel_php7.0: not-affected (7.0.4-5ubuntu2)