6.8
CVE-2015-3330
- EPSS 14.08%
- Veröffentlicht 09.06.2015 18:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.1
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Eus Version 7.1
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 14.08% | 0.961 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
https://support.apple.com/kb/HT205031
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
http://www.securitytracker.com/id/1033703
https://support.apple.com/HT205267
http://php.net/ChangeLog-5.php
http://rhn.redhat.com/errata/RHSA-2015-1066.html
http://rhn.redhat.com/errata/RHSA-2015-1135.html
https://security.gentoo.org/glsa/201606-10
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.html
http://www.ubuntu.com/usn/USN-2572-1
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00004.html
http://rhn.redhat.com/errata/RHSA-2015-1186.html
http://rhn.redhat.com/errata/RHSA-2015-1187.html
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=809610f5ea38a83b284e1125d1fff129bdd615e7
http://openwall.com/lists/oss-security/2015/04/17/7
http://www.securityfocus.com/bid/74204
https://bugs.php.net/bug.php?id=68486
https://bugs.php.net/bug.php?id=69218