CVE-2015-3330: Input Validation
The phphandler function in sapi/apache2handler/sapiapache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3330?
CVE-2015-3330 has a severity rating that indicates it can cause denial of service and potentially allow for arbitrary code execution.
How do I fix CVE-2015-3330?
To fix CVE-2015-3330, upgrade PHP to version 5.4.40 or higher, 5.5.24 or higher, or 5.6.8 or higher.
Which versions of PHP are affected by CVE-2015-3330?
CVE-2015-3330 affects PHP versions before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8.
Can CVE-2015-3330 lead to remote attacks?
Yes, CVE-2015-3330 allows remote attackers to cause application crashes and possibly execute arbitrary code.
What platforms are affected by CVE-2015-3330?
CVE-2015-3330 impacts various platforms including Oracle Linux, Red Hat Enterprise Linux, and macOS Yosemite running vulnerable PHP versions.