CVE-2015-8879 PUBLISHED

The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging use of the odbc_fetch_array function to access a certain type of Microsoft SQL Server table.

EPSS 1.62% · 81.7th percentile

Risk Scores

EPSS Score
1.62%
81.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSphp50, 5.5.3+dfsg-1ubuntu2, 5.5.3+dfsg-1ubuntu3

Timeline

References

Open in Interactive Console →