Wind River Support Network

HomeDefectsLIN6-11355
Fixed

LIN6-11355 : Security Advisory - php - CVE-2015-4644

Created: May 31, 2016    Updated: Dec 3, 2018
Resolved Date: Jun 26, 2016
Found In Version: 6.0.0.29
Fix Version: 6.0.0.31
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.<a href=http://cwe.mitre.org/data/definitions/476.html>CWE-476: NULL Pointer Dereference</a>

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4644

Other Downloads


Live chat
Online