Bugzilla – Bug 981055
VUL-0: CVE-2015-8878: php5, php53: main/php_open_temporary_file.c does not ensure thread safety
Last modified: 2016-08-10 07:23:43 UTC
CVE-2015-8878 main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8878 https://bugs.php.net/bug.php?id=70002
bugbot adjusting priority
No supported php contain fix for php bug 66048, so we are not affected, see comments: [2015-07-24 20:27 UTC] php_150725 at ayd dot jp [2015-07-27 14:15 UTC] ab@php.net [2015-07-27 15:05 UTC] jpauli@php.net