USN-3566-1
Advisory lineage Upstream: 6 Downstream: 0
Published: 12 Feb 2018, 15:29
Last modified:22 Apr 2026, 09:43
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
12 Feb 2018, 15:29
Published
Vulnerability first disclosed
22 Apr 2026, 09:43
Last Modified
Vulnerability information updated
Description
php5 vulnerabilities It was discovered that PHP incorrectly handled the PHAR 404 error page. A remote attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. (CVE-2018-5712) It was discovered that PHP incorrectly handled memory when unserializing certain data. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-12933) It was discovered that PHP incorrectly handled 'front of' and 'back of' date directives. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2017-16642)
Affected Systems
- ubuntu•php5
< 5.5.9+dfsg-1ubuntu4.23