CVE-2016-9138 PUBLISHED

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

EPSS 4.30% · 88.8th percentile

Risk Scores

EPSS Score
4.30%
88.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSphp50, 5.5.3+dfsg-1ubuntu2, 5.5.3+dfsg-1ubuntu3
Ubuntu:Pro:18.04:LTSphp7.27.2.24-0ubuntu0.18.04.17+esm12, 0, 7.2.1-1ubuntu2
Ubuntu:Pro:16.04:LTSphp7.07.0.33-0ubuntu0.16.04.16+esm1, 7.0.33-0ubuntu0.16.04.16+esm2, 7.0.33-0ubuntu0.16.04.16+esm3

Timeline

References

Open in Interactive Console →