CVE-2016-5773 (retired)

Priority
Description
php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23,
and 7.x before 7.0.8 improperly interacts with the unserialize
implementation and garbage collection, which allows remote attackers to
execute arbitrary code or cause a denial of service (use-after-free and
application crash) via crafted serialized data containing a ZipArchive
object.
Notes
 mdeslaur> Applications should never deserialize unauthenticated data.
 mdeslaur> precise needs backported fix
 mdeslaur> we will not be fixing this in Ubuntu 12.04 LTS. We recommend
 mdeslaur> validating untrusted data before unserializing.
Package
Source: php5 (LP Ubuntu Debian)
Upstream:released (5.6.23)
Ubuntu 14.04 LTS (Trusty Tahr):released (5.5.9+dfsg-1ubuntu4.19)
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Patches:
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=f6aef68089221c5ea047d4a74224ee3deead99a6
Package
Upstream:released (7.0.8)
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (7.0.8-0ubuntu0.16.04.1)
Patches:
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=f6aef68089221c5ea047d4a74224ee3deead99a6
More Information

Updated: 2019-03-26 12:22:17 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)