The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.
{
"binaries": [
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libapache2-mod-php5"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libapache2-mod-php5-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libapache2-mod-php5filter"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libapache2-mod-php5filter-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libphp5-embed"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "libphp5-embed-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php-pear"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-cgi"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-cgi-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-cli"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-cli-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-common"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-common-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-curl"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-curl-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-dbg"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-dev"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-dev-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-enchant"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-enchant-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-fpm"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-fpm-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-gd"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-gd-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-gmp"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-gmp-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-intl"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-intl-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-ldap"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-ldap-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-mysql"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-mysql-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-mysqlnd"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-mysqlnd-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-odbc"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-odbc-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-pgsql"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-pgsql-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-pspell"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-pspell-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-readline"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-readline-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-recode"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-recode-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-snmp"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-snmp-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-sqlite"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-sqlite-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-sybase"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-sybase-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-tidy"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-tidy-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-xmlrpc"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-xmlrpc-dbgsym"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-xsl"
},
{
"binary_version": "5.5.9+dfsg-1ubuntu4.20",
"binary_name": "php5-xsl-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "libapache2-mod-php7.0"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "libapache2-mod-php7.0-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "libphp7.0-embed"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "libphp7.0-embed-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-bcmath"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-bcmath-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-bz2"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-bz2-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-cgi"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-cgi-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-cli"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-cli-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-common"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-common-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-curl"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-curl-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-dba"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-dba-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-dev"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-enchant"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-enchant-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-fpm"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-fpm-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-gd"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-gd-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-gmp"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-gmp-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-imap"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-imap-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-interbase"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-interbase-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-intl"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-intl-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-json"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-json-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-ldap"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-ldap-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mbstring"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mbstring-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mcrypt"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mcrypt-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mysql"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-mysql-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-odbc"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-odbc-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-opcache"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-opcache-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-pgsql"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-pgsql-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-phpdbg"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-phpdbg-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-pspell"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-pspell-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-readline"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-readline-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-recode"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-recode-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-snmp"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-snmp-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-soap"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-soap-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-sqlite3"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-sqlite3-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-sybase"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-sybase-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-tidy"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-tidy-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-xml"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-xml-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-xmlrpc"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-xmlrpc-dbgsym"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-xsl"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-zip"
},
{
"binary_version": "7.0.13-0ubuntu0.16.04.1",
"binary_name": "php7.0-zip-dbgsym"
}
],
"availability": "No subscription required"
}