Red Hat Security Advisory 2016-0457-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Multiple flaws were discovered in the way PHP performed object unserialization. Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code. Multiple flaws were found in the way the way PHP's Phar extension parsed Phar archives. A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened.
fabe6c8495064f5b62e36b8ab91356d386aff7c7f20e82513294b65ff3b82aa8
Ubuntu Security Notice 2758-1 - It was discovered that the PHP phar extension incorrectly handled certain files. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service. It was discovered that the PHP phar extension incorrectly handled certain filepaths. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
1fd293d881cea98cd6659c2b1a769ba634f267d1f989e5256cc760a12d6e2823
Debian Linux Security Advisory 3344-1 - Multiple vulnerabilities have been discovered in the PHP language.
336d50d6256b315b13a267027575d849aa84b77d54fa92fb507a883c990583a8