CVE-2014-3515
Last modified
CVE-2014-3515 is a vulnerability of currently unknown severity. The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.. EPSS estimates a 30.13% chance of exploitation in the next 30 days.
Description
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | < 5.3.29 |
| Php | Php | >= 5.4.0, < 5.4.30 |
| Php | Php | >= 5.5.0, < 5.5.14 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
References
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59794Third Party Advisory
- http://secunia.com/advisories/59831Third Party Advisory
- http://secunia.com/advisories/60998Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683486Third Party Advisory
- http://www.debian.org/security/2014/dsa-2974Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlThird Party Advisory
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securityfocus.com/bid/68237Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=67492Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141017844705317&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59794Third Party Advisory
- http://secunia.com/advisories/59831Third Party Advisory
- http://secunia.com/advisories/60998Third Party Advisory
- http://support.apple.com/kb/HT6443Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683486Third Party Advisory
- http://www.debian.org/security/2014/dsa-2974Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlThird Party Advisory
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securityfocus.com/bid/68237Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=67492Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3515?
How severe is CVE-2014-3515?
How do I fix CVE-2014-3515?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3509Race condition in the ssl_parse_serverhello_tlsext function …
- CVE-2014-3510The ssl3_send_client_key_exchange function in s3_clnt.c in O…
- CVE-2014-3511The ssl23_get_client_hello function in s23_srvr.c in OpenSSL…
- CVE-2014-3512Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP…
- CVE-2014-3513Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenS…
- CVE-2014-3514activerecord/lib/active_record/relation/query_methods.rb in …
- CVE-2014-3516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-3517api/metadata/handler.py in OpenStack Compute (Nova) before 2…
- CVE-2014-3518jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss…
- CVE-2014-3519The open_by_handle_at function in vzkernel before 042stab090…
- CVE-2014-3520OpenStack Identity (Keystone) before 2013.2.4, 2014.x before…
- CVE-2014-3521The component in (1) /luci/homebase and (2) /luci/cluster me…
Are you affected by CVE-2014-3515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
