Vulnerability Description
main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 5.5.0, < 5.5.28 |
Related Weaknesses (CWE)
References
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- https://bugs.php.net/bug.php?id=70002Issue TrackingVendor Advisory
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- https://bugs.php.net/bug.php?id=70002Issue TrackingVendor Advisory
FAQ
What is CVE-2015-8878?
CVE-2015-8878 is a vulnerability with a CVSS score of 5.9 (MEDIUM). main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory co...
How severe is CVE-2015-8878?
CVE-2015-8878 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8878?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php.