CVE-2016-9138
04.01.2017, 20:59
PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 ≤ 5.6.27 |
php | php | 7.0.0 |
php | php | 7.0.1 |
php | php | 7.0.2 |
php | php | 7.0.3 |
php | php | 7.0.4 |
php | php | 7.0.5 |
php | php | 7.0.6 |
php | php | 7.0.7 |
php | php | 7.0.8 |
php | php | 7.0.9 |
php | php | 7.0.10 |
php | php | 7.0.11 |
php | php | 7.0.12 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
php5 |
| ||||||||||||||||||||||||||||||||||||||
php7.0 |
| ||||||||||||||||||||||||||||||||||||||
php7.2 |
| ||||||||||||||||||||||||||||||||||||||
php7.4 |
| ||||||||||||||||||||||||||||||||||||||
php8.0 |
| ||||||||||||||||||||||||||||||||||||||
php8.1 |
|
Common Weakness Enumeration