main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-05-22T01:00:00Z

Updated: 2024-09-17T01:01:58.847Z

Reserved: 2016-05-21T00:00:00Z

Link: CVE-2015-8878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-05-22T01:59:10.307

Modified: 2019-02-14T18:47:03.540

Link: CVE-2015-8878

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-07-06T00:00:00Z

Links: CVE-2015-8878 - Bugzilla