main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2016-05-22T01:00:00Z
Updated: 2024-09-17T01:01:58.847Z
Reserved: 2016-05-21T00:00:00Z
Link: CVE-2015-8878
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2016-05-22T01:59:10.307
Modified: 2019-02-14T18:47:03.540
Link: CVE-2015-8878
Redhat