CVE-2014-3515
Last modified
CVE-2014-3515 is a vulnerability of currently unknown severity. The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.. EPSS estimates a 30.13% chance of exploitation in the next 30 days.
Description
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | < 5.3.29 |
| Php | Php | >= 5.4.0, < 5.4.30 |
| Php | Php | >= 5.5.0, < 5.5.14 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
References
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59794Third Party Advisory
- http://secunia.com/advisories/59831Third Party Advisory
- http://secunia.com/advisories/60998Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683486Third Party Advisory
- http://www.debian.org/security/2014/dsa-2974Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlThird Party Advisory
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securityfocus.com/bid/68237Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=67492Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59794Third Party Advisory
- http://secunia.com/advisories/59831Third Party Advisory
- http://secunia.com/advisories/60998Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683486Third Party Advisory
- http://www.debian.org/security/2014/dsa-2974Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlThird Party Advisory
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securityfocus.com/bid/68237Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=67492Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3515?
How severe is CVE-2014-3515?
How do I fix CVE-2014-3515?
Are you affected by CVE-2014-3515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
