cbcvebase.
CVE-2015-4603
published 2016-05-16

CVE-2015-4603: The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to…

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
11.00%
95.4th percentile
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
phpphp<= 5.4.39
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp
phpphp

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via PHP's unserialize() function processing specially crafted input that causes a type confusion in exception::getTraceAsString()
  • The vulnerable code path is in Zend/zend_exceptions.c — monitor for unexpected data types passed through unserialize() leading into exception trace handling
  • The upstream fix commit can be used as a patch-level detection reference to identify unpatched PHP instances
  • ·PHP versions before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 are affected; Red Hat Enterprise Linux 5 packages (php, php53) are marked 'Will not fix'
  • ·Exploitation requires that attacker-controlled data reaches the unserialize() function in a PHP application

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.