PHP ZipArchive::getArchiveComment() NULL Pointer Dereference Denial Of Service Vulnerability
Publish Date: 31 maja 2016
Severity: : Medium
Advisory Date: 31 maja 2016
DESCRIPTION
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1005434