vendor:
PHP
by:
Taoguang Chen
7,5
CVSS
HIGH
Use After Free
416
CWE
Product Name: PHP
Affected Version From: PHP 5.6
Affected Version To: PHP 5.6.12
Patch Exists: YES
Related CWE: N/A
CPE: 2.6.39
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MacOSX 10.11
2015
Use After Free Vulnerability in unserialize() with GMP
A use-after-free vulnerability was discovered in unserialize() with GMP object's deserialization that can be abused for leaking arbitrary memory blocks or execute arbitrary code remotely.
Mitigation:
Upgrade to PHP 5.6.13 or later