PHP ZipArchive::getArchiveComment() NULL Pointer Dereference Denial Of Service Vulnerability
Publish Date: 31 mai 2016
Gravité: : Medium
Date du conseil: 31 mai 2016
Description
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
Information Exposure Rating:
Apply associated Trend Micro DPI Rules.
Solutions
Trend Micro Deep Security DPI Rule Number: 1005434