Double free in PHP - CVE-2015-8880

 

Double free in PHP - CVE-2015-8880

Published: March 1, 2022 / Updated: June 8, 2025


Vulnerability identifier: #VU110269
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8880
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.


Affected software

PHP

How to mitigate CVE-2015-8880

Install update from vendor's website.

PHP - update to 7.0.1

External References

Related Security Bulletins