Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2016-05-22T01:00:00

Updated: 2018-01-04T19:57:01

Reserved: 2016-05-21T00:00:00


Link: CVE-2015-8876

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2016-05-22T01:59:07.697

Modified: 2019-02-14T18:48:13.963


Link: CVE-2015-8876

JSON object: View

cve-icon Redhat Information

No data.