Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2017/02/02/3 | third party advisory mailing list |
https://www.revive-adserver.com/security/revive-sa-2017-001/ | patch vendor advisory |
http://www.securityfocus.com/bid/95875 | vdb entry |