CVE-2014-3669

Priority
Description
Integer overflow in the object_custom function in
ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18,
and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service
(application crash) or possibly execute arbitrary code via an argument to
the unserialize function that triggers calculation of a large length value.
Assigned-to
mdeslaur
Notes
Package
Source: php5 (LP Ubuntu Debian)
Upstream:released (5.4.34, 5.5.18, 5.6.1)
Ubuntu 14.04 ESM (Trusty Tahr):released (5.5.9+dfsg-1ubuntu4.5)
Patches:
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=9aa90145239bae82d2af0a99fdae4ab27eb5f4f2 (5.5)
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=56754a7f9eba0e4f559b6ca081d9f2a447b3f159 (5.4)
More Information

Updated: 2019-12-05 18:37:34 UTC (commit dd38ff22974aae499eb50644b9d5a2817483cbdb)