CVE-2016-5771

Priority
Description
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before
5.6.23 improperly interacts with the unserialize implementation and garbage
collection, which allows remote attackers to execute arbitrary code or
cause a denial of service (use-after-free and application crash) via
crafted serialized data.
Notes
sarnoldApplications should never deserialize unauthenticated data.
mdeslaurdoes not affect 7.0.x
precise needs backported fix
we will not be fixing this in Ubuntu 12.04 LTS. We recommend
validating untrusted data before unserializing.
Package
Source: php5 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 14.04 ESM (Trusty Tahr):released (5.5.9+dfsg-1ubuntu4.19)
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Patches:
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=3f627e580acfdaf0595ae3b115b8bec677f203ee
Package
Upstream:needs-triage
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected
More Information

Updated: 2020-03-18 22:45:45 UTC (commit 2ea7df7bd1e69e1e489978d2724a936eb3faa1b8)