ALAS-2015-494 --- php55ID: oval:org.secpod.oval:def:1200143 | Date: (C)2015-12-28 (M)2024-02-19 |
Class: PATCH | Family: unix |
A heap-based buffer overflow was found in glibc"s __nss_hostname_digits_dots function, which is used by the gethostbyname and gethostbyname2 glibc function calls. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application. A use-after-free flaw was found in the unserialize function of PHP"s DateTimeZone implementation. A malicious script author could possibly use this flaw to disclose certain portions of server memory
Platform: |
Amazon Linux AMI |