Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-4600


The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in the (1) SoapClient::__getLastRequest, (2) SoapClient::__getLastResponse, (3) SoapClient::__getLastRequestHeaders, (4) SoapClient::__getLastResponseHeaders, (5) SoapClient::__getCookies, and (6) SoapClient::__setCookie methods.


Published

2016-05-16T10:59:07.753

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_hpc_node 7.0 Yes
Operating System redhat enterprise_linux_hpc_node_eus 7.1 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_eus 7.1 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application php php ≤ 5.4.39 Yes
Application php php 5.5.0 Yes
Application php php 5.5.1 Yes
Application php php 5.5.2 Yes
Application php php 5.5.3 Yes
Application php php 5.5.4 Yes
Application php php 5.5.5 Yes
Application php php 5.5.6 Yes
Application php php 5.5.7 Yes
Application php php 5.5.8 Yes
Application php php 5.5.9 Yes
Application php php 5.5.10 Yes
Application php php 5.5.11 Yes
Application php php 5.5.12 Yes
Application php php 5.5.13 Yes
Application php php 5.5.14 Yes
Application php php 5.5.15 Yes
Application php php 5.5.16 Yes
Application php php 5.5.17 Yes
Application php php 5.5.18 Yes
Application php php 5.5.19 Yes
Application php php 5.5.20 Yes
Application php php 5.5.21 Yes
Application php php 5.5.22 Yes
Application php php 5.5.23 Yes
Application php php 5.6.0 Yes
Application php php 5.6.1 Yes
Application php php 5.6.2 Yes
Application php php 5.6.3 Yes
Application php php 5.6.4 Yes
Application php php 5.6.5 Yes
Application php php 5.6.6 Yes
Application php php 5.6.7 Yes

References