PHP ZipArchive::getArchiveComment() NULL Pointer Dereference Denial Of Service Vulnerability

  Severity: MEDIUM
  Advisory Date: MAY 31, 2016

  DESCRIPTION

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005434

Featured Stories