PublicDateAtUSN: 2017-01-11 Candidate: CVE-2016-7478 PublicDate: 2017-01-11 06:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7478 http://blog.checkpoint.com/2016/12/27/check-point-discovers-three-zero-day-vulnerabilities-web-programming-language-php-7 http://blog.checkpoint.com/wp-content/uploads/2016/12/PHP_Technical_Report.pdf https://www.youtube.com/watch?v=LDcaPstAuPk https://ubuntu.com/security/notices/USN-3196-1 Description: Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876. Ubuntu-Description: Notes: mdeslaur> can't reproduce with 7.0.13, assumed fixed mdeslaur> php5 needs CVE-2016-9137 to be applied Bugs: https://bugs.php.net/bug.php?id=73093 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commit;h=40e7baab3c90001beee4c8f0ed0ef79ad18ee0d6 upstream_php5: needs-triage precise_php5: released (5.3.10-1ubuntu3.26) trusty_php5: released (5.5.9+dfsg-1ubuntu4.21) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.21) vivid/ubuntu-core_php5: DNE vivid/stable-phone-overlay_php5: DNE xenial_php5: DNE yakkety_php5: DNE devel_php5: DNE Patches_php7.0: upstream: http://git.php.net/?p=php-src.git;a=commit;h=eca84946a4e7269d59ea2d79b5f42117de89ae74 (possibly) upstream_php7.0: needs-triage precise_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/ubuntu-core_php7.0: DNE vivid/stable-phone-overlay_php7.0: DNE xenial_php7.0: not-affected (7.0.13-0ubuntu0.16.04.1) esm-infra/xenial_php7.0: not-affected (7.0.13-0ubuntu0.16.04.1) yakkety_php7.0: not-affected (7.0.13-0ubuntu0.16.10.1) devel_php7.0: not-affected (7.0.14-2ubuntu1)