PublicDateAtUSN: 2016-05-16 Candidate: CVE-2015-8873 PublicDate: 2016-05-16 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8873 http://php.net/ChangeLog-5.php https://ubuntu.com/security/notices/USN-3045-1 Description: Stack consumption vulnerability in Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to cause a denial of service (segmentation fault) via recursive method calls. Ubuntu-Description: Notes: sbeattie> recursion through unserializing exceptions Bugs: https://bugs.php.net/bug.php?id=69793 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commit;h=4d2278143a08b7522de9471d0f014d7357c28fea upstream: http://git.php.net/?p=php-src.git;a=commit;h=f1acac154ac7684bc908fc2ad8962372c9d4e312 upstream: http://git.php.net/?p=php-src.git;a=commit;h=0a21b5d97039945a9e5dc683f2f5e8b379f07ada upstream: http://git.php.net/?p=php-src.git;a=commit;h=da5321013c4dbac0faac12f78b28f662a91b4bc1 upstream_php5: released (5.6.12+dfsg-1) precise_php5: released (5.3.10-1ubuntu3.24) trusty_php5: released (5.5.9+dfsg-1ubuntu4.19) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.19) vivid/stable-phone-overlay_php5: DNE vivid/ubuntu-core_php5: DNE wily_php5: ignored (reached end-of-life) xenial_php5: DNE devel_php5: DNE