#VU12900 Use-after-free error in PHP


Published: 2020-05-18

Vulnerability identifier: #VU12900

Vulnerability risk: High

CVSSv3.1:

CVE-ID: CVE-2016-7479

CWE-ID:

Exploitation vector: Network

Exploit availability:

Vulnerable software:
PHP
Universal components / Libraries / Scripting languages

Vendor: PHP Group

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to resizing the 'properties' hash table of a serialized object during the unserialization process. A remote attacker can trigger use-after-free error and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation
Install update from vendor's website.

Vulnerable software versions

PHP: 7.0.0 - 7.0.30, 7.1.0 - 7.1.17, 7.2.0 - 7.2.5


Fixed software versions

CPE

External links
http://bugs.php.net/bug.php?id=73092


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability