CVE-2016-3185: Input Validation
Fixed bug (Type Confusion Vulnerability - SOAP / makehttpsoaprequest()). (CVE-2016-3185)
Other sources
The makehttpsoaprequest function in ext/soap/phphttp.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized cookies data, related to the SoapClient::call method in ext/soap/soap.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3185?
CVE-2016-3185 is classified as a high-severity vulnerability due to its potential impact on affected systems.
How do I fix CVE-2016-3185?
To fix CVE-2016-3185, upgrade to PHP version 5.4.44, 5.5.28, 5.6.12, or 7.0.4 or later.
Which versions of PHP are affected by CVE-2016-3185?
CVE-2016-3185 affects PHP versions before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4.
What type of vulnerabilities does CVE-2016-3185 address?
CVE-2016-3185 addresses a Type Confusion vulnerability in the SOAP extension of PHP.
What effects can CVE-2016-3185 have on an application?
CVE-2016-3185 can allow remote attackers to obtain sensitive information from affected applications.