CVE Vulnerabilities

CVE-2015-4603

Published: May 16, 2016 | Modified: Apr 22, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a type confusion issue.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.4.39 (including)
Php Php 5.5.0 (including) 5.5.0 (including)
Php Php 5.5.1 (including) 5.5.1 (including)
Php Php 5.5.2 (including) 5.5.2 (including)
Php Php 5.5.3 (including) 5.5.3 (including)
Php Php 5.5.4 (including) 5.5.4 (including)
Php Php 5.5.5 (including) 5.5.5 (including)
Php Php 5.5.6 (including) 5.5.6 (including)
Php Php 5.5.7 (including) 5.5.7 (including)
Php Php 5.5.8 (including) 5.5.8 (including)
Php Php 5.5.9 (including) 5.5.9 (including)
Php Php 5.5.10 (including) 5.5.10 (including)
Php Php 5.5.11 (including) 5.5.11 (including)
Php Php 5.5.12 (including) 5.5.12 (including)
Php Php 5.5.13 (including) 5.5.13 (including)
Php Php 5.5.14 (including) 5.5.14 (including)
Php Php 5.5.15 (including) 5.5.15 (including)
Php Php 5.5.16 (including) 5.5.16 (including)
Php Php 5.5.17 (including) 5.5.17 (including)
Php Php 5.5.18 (including) 5.5.18 (including)
Php Php 5.5.19 (including) 5.5.19 (including)
Php Php 5.5.20 (including) 5.5.20 (including)
Php Php 5.5.21 (including) 5.5.21 (including)
Php Php 5.5.22 (including) 5.5.22 (including)
Php Php 5.5.23 (including) 5.5.23 (including)
Php Php 5.6.0 (including) 5.6.0 (including)
Php Php 5.6.1 (including) 5.6.1 (including)
Php Php 5.6.2 (including) 5.6.2 (including)
Php Php 5.6.3 (including) 5.6.3 (including)
Php Php 5.6.4 (including) 5.6.4 (including)
Php Php 5.6.5 (including) 5.6.5 (including)
Php Php 5.6.6 (including) 5.6.6 (including)
Php Php 5.6.7 (including) 5.6.7 (including)

References