CVE Vulnerabilities

CVE-2015-6835

Published: May 16, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.6.0-alpha1 (including)5.6.0-alpha1 (including)
PhpPhp5.6.0-alpha2 (including)5.6.0-alpha2 (including)
PhpPhp5.6.0-alpha3 (including)5.6.0-alpha3 (including)
PhpPhp5.6.0-alpha4 (including)5.6.0-alpha4 (including)
PhpPhp5.6.0-alpha5 (including)5.6.0-alpha5 (including)
PhpPhp5.6.0-beta1 (including)5.6.0-beta1 (including)
PhpPhp5.6.0-beta2 (including)5.6.0-beta2 (including)
PhpPhp5.6.0-beta3 (including)5.6.0-beta3 (including)
PhpPhp5.6.0-beta4 (including)5.6.0-beta4 (including)
PhpPhp5.6.1 (including)5.6.1 (including)
PhpPhp5.6.2 (including)5.6.2 (including)
PhpPhp5.6.3 (including)5.6.3 (including)
PhpPhp5.6.4 (including)5.6.4 (including)
PhpPhp5.6.5 (including)5.6.5 (including)
PhpPhp5.6.6 (including)5.6.6 (including)
PhpPhp5.6.7 (including)5.6.7 (including)
PhpPhp5.6.8 (including)5.6.8 (including)
PhpPhp5.6.9 (including)5.6.9 (including)
PhpPhp5.6.10 (including)5.6.10 (including)
PhpPhp5.6.11 (including)5.6.11 (including)
PhpPhp5.6.12 (including)5.6.12 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-php-0:5.6.5-8.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-php56-php-0:5.6.5-8.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-php56-php-0:5.6.5-8.el7*
Php5Ubuntudevel*
Php5Ubuntuesm-infra-legacy/trusty*
Php5Ubuntuprecise*
Php5Ubuntutrusty*
Php5Ubuntutrusty/esm*
Php5Ubuntuupstream*
Php5Ubuntuvivid*

References