CVE-2015-4601: Critical severity red hat enterprise linux desktop vulnerability
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/phpencoding.c, (2) ext/soap/phphttp.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4601?
CVE-2015-4601 has a high severity due to its potential for remote denial of service and arbitrary code execution.
How do I fix CVE-2015-4601?
To fix CVE-2015-4601, upgrade PHP to version 5.6.7 or later.
Which PHP versions are affected by CVE-2015-4601?
CVE-2015-4601 affects all PHP versions prior to 5.6.7.
Can CVE-2015-4601 be exploited remotely?
Yes, CVE-2015-4601 can be exploited remotely, allowing attackers to cause a denial of service.
What types of applications are at risk from CVE-2015-4601?
Applications using affected PHP versions, especially those utilizing the SOAP extension, are at risk from CVE-2015-4601.