Use-after-free in PHP - CVE-2010-2093

 

Use-after-free in PHP - CVE-2010-2093

Published: December 7, 2010 / Updated: June 8, 2025


Vulnerability identifier: #VU110297
CSH Severity: Medium
CVSS v4.0:
CVE-ID: CVE-2010-2093
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: PHP Group
Affected software:
PHP

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a stream context structure that is freed before destruction occurs. A context-dependent attackers can cause a denial of service (crash).

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


How to mitigate CVE-2010-2093

Install update from vendor's website.

Sources