Linux Distros Unpatched Vulnerability : CVE-2015-4148
Discription

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted serialized data with an int data type, related to a type confusion issue. (CVE-2015-4148) Note that Nessus relies on the presence of the package as reported by the…Read More

Back to Main

Subscribe for the latest news: