Use-after-free error in PHP - CVE-2015-0273
Published: November 27, 2018 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6. A remote attacker can trigger memory corruption via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
php5 (Ubuntu package)
php
Fedora
How to mitigate CVE-2015-0273
php5 (Ubuntu package) - addressed in versions 5.3.2-1ubuntu4.29, 5.3.10-1ubuntu3.17, 5.5.9+dfsg-1ubuntu4.7, 5.5.12+dfsg-2ubuntu4.3
php - update to 5.6.6-1.fc21