RULE(RULE ID:333052)

Rule General Information
Release Date: 2021-03-26
Rule Name: PHP DateTimeZone Object timezone Unserialize Type Confusion Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A code execution vulnerability has been reported in PHP. The vulnerability is due to a type confusion error when handling serialized DateTimeZone objects within the unserialize() function. A remote attacker can exploit the vulnerability by sending crafted serialized data to a web application running a vulnerable version of PHP. A successful attack will result in remote code execution under the context of the service running PHP.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.