CVE-2014-3515

NameCVE-2014-3515
DescriptionThe SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDLA-0018-1, DSA-2974-1
NVD severityhigh (attack range: remote)
Debian/oldoldstablepackage php5 is vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php5 (PTS)squeeze, squeeze (security)5.3.3-7+squeeze19vulnerable
squeeze (lts)5.3.3.1-7+squeeze26fixed
wheezy5.4.36-0+deb7u1fixed
wheezy (security)5.4.41-0+deb7u1fixed
jessie5.6.7+dfsg-1fixed
jessie (security)5.6.9+dfsg-0+deb8u1fixed
stretch, sid5.6.9+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php5source(unstable)5.6.0~rc2+dfsg-1high
php5sourcesqueeze5.3.3-7+squeeze21high
php5sourcewheezy5.4.4-14+deb7u12highDSA-2974-1

Notes

https://bugs.php.net/bug.php?id=67492

Search for package or bug name: Reporting problems