Use-after-free in PHP - CVE-2015-0231
Published: November 27, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability exists due to гse-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5. A remote attacker can trigger memory corruption via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an objecе. Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
Slackware Linux
Fedora
php5 (Ubuntu package)
php
How to mitigate CVE-2015-0231
php5 (Ubuntu package) - addressed in versions 5.3.10-1ubuntu3.16, 5.5.9+dfsg-1ubuntu4.6, 5.5.12+dfsg-2ubuntu4.2
php - addressed in versions 5.6.5-1.fc21, 5.6.7-1.fc21, 5.6.7-2.fc22
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Ubuntu update for PHP
- Amazon Linux AMI update for php54
- Amazon Linux AMI update for php55
- Amazon Linux AMI update for php56
- Amazon Linux AMI update for php55
- Amazon Linux AMI update for php54
- Gentoo update for PHP
- Slackware Linux update for php
- Fedora 21 update for php
- Fedora 22 update for php
- Fedora 21 update for php