CVE-2015-8873: Input Validation
Published May 16, 2016
·Updated
Stack consumption vulnerability in Zend/zendexceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to cause a denial of service (segmentation fault) via recursive method calls.
Affected Software
4 affected components
PHP PHP<5.4.44
PHP PHP>=5.5.0<5.5.28
PHP PHP>=5.6.0<5.6.12
openSUSE Leap=42.1
Remediation
Event History
May 16, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8873?
CVE-2015-8873 has a high severity rating due to its potential to cause a denial of service through segmentation faults.
2
How do I fix CVE-2015-8873?
To mitigate CVE-2015-8873, upgrade PHP to version 5.4.44 or later, 5.5.28 or later, or 5.6.12 or later.
3
What systems are affected by CVE-2015-8873?
CVE-2015-8873 affects PHP versions prior to 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12.
4
Can CVE-2015-8873 be exploited remotely?
Yes, CVE-2015-8873 can be exploited remotely, allowing attackers to initiate recursive method calls.
5
What type of vulnerability is CVE-2015-8873?
CVE-2015-8873 is classified as a stack consumption vulnerability.