Arbitrary code execution in PHP-Nuke - CVE-2016-7411
Published: September 19, 2016 / Updated: September 20, 2016
Vulnerability identifier: #VU529
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2016-7411
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote or local user to cause arbitrary code execution on the target system.
The weakness is caused by deserialized object destruction that may result in memory corruption error and allows a malicious user to execute arbitrary code.
Successful explotation of the vulnerability may result in arbitrary code execution on the vulnerable system.
The weakness is caused by deserialized object destruction that may result in memory corruption error and allows a malicious user to execute arbitrary code.
Successful explotation of the vulnerability may result in arbitrary code execution on the vulnerable system.
Affected software
PHP-Nuke
Arch Linux
SUSE Linux
Slackware Linux
Fedora
php (Alpine package)
php
Arch Linux
SUSE Linux
Slackware Linux
Fedora
php (Alpine package)
php
How to mitigate CVE-2016-7411
Update to 5.6.26.
http://php.net/ChangeLog-5.php#5.6.26
Update to 7.0.11.
http://php.net/ChangeLog-7.php#7.0.11
http://php.net/ChangeLog-5.php#5.6.26
Update to 7.0.11.
http://php.net/ChangeLog-7.php#7.0.11
php (Alpine package) - update to 5.6.27-r0
php - addressed in versions 5.6.26-1.fc23, 5.6.26-1.fc24
php - addressed in versions 5.6.26-1.fc23, 5.6.26-1.fc24
External References
Related Security Bulletins
- Arch Linux update for php
- Slackware Linux update for php
- OpenSUSE Linux update for php5
- SUSE Linux update for php5
- SUSE Linux update for php53
- OpenSUSE Linux update for php5
- SUSE Linux update for php5
- Arbitrary code execution in php (Alpine package)
- SUSE Linux update for php53
- Fedora 24 update for php
- Fedora 23 update for php