Vulnerability Name:

CVE-2015-6835

Assigned:2015-09-08
Published:2016-05-16
Updated:2017-11-03
Summary:The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.
CVSS v3 Severity:9.8 Critical (CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
References:Source: CONFIRM
Type: UNKNOWN
http://php.net/ChangeLog-5.php

Source: DEBIAN
Type: UNKNOWN
DSA-3358

Source: BID
Type: UNKNOWN
76734

Source: SECTRACK
Type: UNKNOWN
1033548

Source: CONFIRM
Type: UNKNOWN
https://bugs.php.net/bug.php?id=70219

Source: XF
Type: UNKNOWN
php-cve20156835-code-exec(106364)

Source: GENTOO
Type: UNKNOWN
GLSA-201606-10

Vulnerable Configuration:Configuration 1:
  • cpe:/a:php:php:5.6.0:alpha1:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:alpha2:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:alpha3:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:alpha4:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:alpha5:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.9:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.10:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.11:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.6.12:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:php:php:5.4.44:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:php:php:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha1:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha2:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha3:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha4:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha5:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:alpha6:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.8:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.9:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.14:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.15:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.16:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.17:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.18:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.19:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.20:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.21:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.22:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.23:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.24:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.25:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.26:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.27:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:5.5.28:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20156835
    V
    CVE-2015-6835
    2017-11-24
    oval:com.ubuntu.precise:def:20156835000
    V
    CVE-2015-6835 on Ubuntu 12.04 LTS (precise) - medium.
    2016-05-16
    oval:com.ubuntu.trusty:def:20156835000
    V
    CVE-2015-6835 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-05-16
    oval:org.cisecurity:def:67
    P
    DSA-3358-1 -- php5 -- security update
    2016-02-08
    BACK
    php php 5.6.0 alpha1
    php php 5.6.0 alpha2
    php php 5.6.0 alpha3
    php php 5.6.0 alpha4
    php php 5.6.0 alpha5
    php php 5.6.0 beta1
    php php 5.6.0 beta2
    php php 5.6.0 beta3
    php php 5.6.0 beta4
    php php 5.6.1
    php php 5.6.2
    php php 5.6.3
    php php 5.6.4
    php php 5.6.5
    php php 5.6.6
    php php 5.6.7
    php php 5.6.8
    php php 5.6.9
    php php 5.6.10
    php php 5.6.11
    php php 5.6.12
    php php 5.4.44
    php php 5.5.0
    php php 5.5.0 alpha1
    php php 5.5.0 alpha2
    php php 5.5.0 alpha3
    php php 5.5.0 alpha4
    php php 5.5.0 alpha5
    php php 5.5.0 alpha6
    php php 5.5.0 beta1
    php php 5.5.0 beta2
    php php 5.5.0 beta3
    php php 5.5.0 beta4
    php php 5.5.0 rc1
    php php 5.5.0 rc2
    php php 5.5.1
    php php 5.5.2
    php php 5.5.3
    php php 5.5.4
    php php 5.5.5
    php php 5.5.6
    php php 5.5.7
    php php 5.5.8
    php php 5.5.9
    php php 5.5.10
    php php 5.5.11
    php php 5.5.12
    php php 5.5.13
    php php 5.5.14
    php php 5.5.15
    php php 5.5.16
    php php 5.5.17
    php php 5.5.18
    php php 5.5.19
    php php 5.5.20
    php php 5.5.21
    php php 5.5.22
    php php 5.5.23
    php php 5.5.24
    php php 5.5.25
    php php 5.5.26
    php php 5.5.27
    php php 5.5.28