vendor:
PHP
by:
Taoguang Chen
8.8
CVSS
HIGH
Use After Free Vulnerability
416
CWE
Product Name: PHP
Affected Version From: PHP 5.6 < 5.6.6, PHP 5.5 < 5.5.22, PHP 5.4 < 5.4.38
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2015-0273
CPE: a:php:php:5.6.6
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1218/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1135/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1066/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/apple-osx-adminframework-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apachemodphp-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/php-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/apple-osx-accelerateframework-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2015-0273/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0273/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=81512, https://www.infosecmatter.com/nessus-plugin-library/?id=86654, https://www.infosecmatter.com/nessus-plugin-library/?id=84488, https://www.infosecmatter.com/nessus-plugin-library/?id=81829, https://www.infosecmatter.com/nessus-plugin-library/?id=84489, https://www.infosecmatter.com/nessus-plugin-library/?id=84648, https://www.infosecmatter.com/nessus-plugin-library/?id=84351, https://www.infosecmatter.com/nessus-plugin-library/?id=84345, https://www.infosecmatter.com/nessus-plugin-library/?id=84659, https://www.infosecmatter.com/nessus-plugin-library/?id=124996
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Use After Free Vulnerability in unserialize() with DateTime* [CVE-2015-0273]
A use-after-free vulnerability was discovered in unserialize() with DateTime/DateTimeZone/DateInterval/DatePeriod objects's __wakeup() magic method that can be abused for leaking arbitrary memory blocks or execute arbitrary code remotely.
Mitigation:
Upgrade to PHP 5.6.6, 5.5.22, or 5.4.38