Use-after-free in PHP - CVE-2010-2093

 

Use-after-free in PHP - CVE-2010-2093

Published: December 7, 2010 / Updated: June 8, 2025


Vulnerability identifier: #VU110297
CSH Severity: Medium
CVSS v4: []
CVE-ID: CVE-2010-2093
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a stream context structure that is freed before destruction occurs. A context-dependent attackers can cause a denial of service (crash).

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

PHP
Gentoo Linux
dev-lang/php

How to mitigate CVE-2010-2093

Install update from vendor's website.

PHP - addressed in versions 5.2.13, 5.3.2
dev-lang/php - update to 5.3.8

External References

Related Security Bulletins