Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-php | Aug 30, 2017 | Jan 19, 2016 |
| Apple Osx Apachemodphp | apple-osx-security-update-2015-004-yosemiteapple-osx-security-update-2015-007-mavericksapple-osx-upgrade-latest | Mar 29, 2016 | Mar 29, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-lang-php | Oct 30, 2017 | May 16, 2016 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | May 16, 2016 | |
| Php | php-upgrade-5_4_45php-upgrade-5_5_29php-upgrade-5_6_13 | Jun 3, 2016 | May 16, 2016 | |
| Ubuntu | ubuntu-upgrade-libapache2-mod-php5ubuntu-upgrade-php5-cgiubuntu-upgrade-php5-cliubuntu-upgrade-php5-fpm | Nov 8, 2024 | May 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub