CVE-2016-6295

Published on: 07/25/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:12 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Certain versions of Php from Php contain the following vulnerability:

ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via crafted serialized data, a related issue to CVE-2016-5773.

  • CVE-2016-6295 has been assigned by [email protected] to track the vulnerability - currently rated as - currently rated as CRITICAL severity.

CVSS3 Score: 9.8 - CRITICAL

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 7.5 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL PARTIAL PARTIAL

CVE References

Description Tags Link
About the security content of macOS Sierra 10.12 - Apple Support support.apple.com
text/html
URL Logo CONFIRM support.apple.com/HT207170
72.52.91.13 Git - php-src.git/commit Issue Tracking
Patch
git.php.net
text/xml
URL Logo CONFIRM git.php.net/?p=php-src.git;a=commit;h=cab1c3b3708eead315e033359d07049b23b147a3
PHP: PHP 7 ChangeLog Release Notes
php.net
text/html
URL Logo CONFIRM php.net/ChangeLog-7.php
APPLE-SA-2016-09-20 macOS Sierra 10.12 lists.apple.com
text/html
URL Logo APPLE APPLE-SA-2016-09-20
PHP 'snmp.c' Denial of Service Vulnerability Third Party Advisory
VDB Entry
cve.report (archive)
text/html
URL Logo BID 92094
PHP :: Sec Bug #72479 :: Use After Free Vulnerability in SNMP with GC and unserialize() Exploit
Issue Tracking
Patch
Third Party Advisory
bugs.php.net
text/html
URL Logo CONFIRM bugs.php.net/72479
Debian -- Security Information -- DSA-3631-1 php5 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3631
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:2750
PHP Multiple Flaws Let Remote and Local Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036430
PHP: PHP 5 ChangeLog Release Notes
php.net
text/html
URL Logo CONFIRM php.net/ChangeLog-5.php
oss-security - Re: Fwd: CVE for PHP 5.5.38 issues Mailing List
Patch
openwall.com
text/html
URL Logo MLIST [oss-security] 20160724 Re: Fwd: CVE for PHP 5.5.38 issues
PHP: Multiple vulnerabilities (GLSA 201611-22) — Gentoo security security.gentoo.org
text/html
URL Logo GENTOO GLSA-201611-22

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationPhpPhp5.6.0alpha1AllAll
ApplicationPhpPhp5.6.0alpha2AllAll
ApplicationPhpPhp5.6.0alpha3AllAll
ApplicationPhpPhp5.6.0alpha4AllAll
ApplicationPhpPhp5.6.0alpha5AllAll
ApplicationPhpPhp5.6.0beta1AllAll
ApplicationPhpPhp5.6.0beta2AllAll
ApplicationPhpPhp5.6.0beta3AllAll
ApplicationPhpPhp5.6.0beta4AllAll
ApplicationPhpPhp5.6.1AllAllAll
ApplicationPhpPhp5.6.10AllAllAll
ApplicationPhpPhp5.6.11AllAllAll
ApplicationPhpPhp5.6.12AllAllAll
ApplicationPhpPhp5.6.13AllAllAll
ApplicationPhpPhp5.6.14AllAllAll
ApplicationPhpPhp5.6.15AllAllAll
ApplicationPhpPhp5.6.16AllAllAll
ApplicationPhpPhp5.6.17AllAllAll
ApplicationPhpPhp5.6.18AllAllAll
ApplicationPhpPhp5.6.19AllAllAll
ApplicationPhpPhp5.6.2AllAllAll
ApplicationPhpPhp5.6.20AllAllAll
ApplicationPhpPhp5.6.21AllAllAll
ApplicationPhpPhp5.6.22AllAllAll
ApplicationPhpPhp5.6.23AllAllAll
ApplicationPhpPhp5.6.3AllAllAll
ApplicationPhpPhp5.6.4AllAllAll
ApplicationPhpPhp5.6.5AllAllAll
ApplicationPhpPhp5.6.6AllAllAll
ApplicationPhpPhp5.6.7AllAllAll
ApplicationPhpPhp5.6.8AllAllAll
ApplicationPhpPhp5.6.9AllAllAll
ApplicationPhpPhp7.0.0AllAllAll
ApplicationPhpPhp7.0.1AllAllAll
ApplicationPhpPhp7.0.2AllAllAll
ApplicationPhpPhp7.0.3AllAllAll
ApplicationPhpPhp7.0.4AllAllAll
ApplicationPhpPhp7.0.5AllAllAll
ApplicationPhpPhp7.0.8AllAllAll
ApplicationPhpPhp5.6.0alpha1AllAll
ApplicationPhpPhp5.6.0alpha2AllAll
ApplicationPhpPhp5.6.0alpha3AllAll
ApplicationPhpPhp5.6.0alpha4AllAll
ApplicationPhpPhp5.6.0alpha5AllAll
ApplicationPhpPhp5.6.0beta1AllAll
ApplicationPhpPhp5.6.0beta2AllAll
ApplicationPhpPhp5.6.0beta3AllAll
ApplicationPhpPhp5.6.0beta4AllAll
ApplicationPhpPhp5.6.1AllAllAll
ApplicationPhpPhp5.6.10AllAllAll
ApplicationPhpPhp5.6.11AllAllAll
ApplicationPhpPhp5.6.12AllAllAll
ApplicationPhpPhp5.6.13AllAllAll
ApplicationPhpPhp5.6.14AllAllAll
ApplicationPhpPhp5.6.15AllAllAll
ApplicationPhpPhp5.6.16AllAllAll
ApplicationPhpPhp5.6.17AllAllAll
ApplicationPhpPhp5.6.18AllAllAll
ApplicationPhpPhp5.6.19AllAllAll
ApplicationPhpPhp5.6.2AllAllAll
ApplicationPhpPhp5.6.20AllAllAll
ApplicationPhpPhp5.6.21AllAllAll
ApplicationPhpPhp5.6.22AllAllAll
ApplicationPhpPhp5.6.23AllAllAll
ApplicationPhpPhp5.6.3AllAllAll
ApplicationPhpPhp5.6.4AllAllAll
ApplicationPhpPhp5.6.5AllAllAll
ApplicationPhpPhp5.6.6AllAllAll
ApplicationPhpPhp5.6.7AllAllAll
ApplicationPhpPhp5.6.8AllAllAll
ApplicationPhpPhp5.6.9AllAllAll
ApplicationPhpPhp7.0.0AllAllAll
ApplicationPhpPhp7.0.1AllAllAll
ApplicationPhpPhp7.0.2AllAllAll
ApplicationPhpPhp7.0.3AllAllAll
ApplicationPhpPhp7.0.4AllAllAll
ApplicationPhpPhp7.0.5AllAllAll
ApplicationPhpPhp7.0.8AllAllAll
ApplicationPhpPhpAllAllAllAll
  • cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta1:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta2:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta3:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta4:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.17:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.18:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.19:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.20:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.21:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.22:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.23:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta1:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta2:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta3:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.0:beta4:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.17:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.18:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.19:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.20:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.21:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.22:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.23:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*: