CVE-2014-8142

Php < 5.4.35 - Use After Free

Title source: rule

Description

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.

Exploits (1)

nomisec STUB 2 stars
by 3xp10it · poc
https://github.com/3xp10it/php_cve-2014-8142_cve-2015-0231

Scores

EPSS 0.8828
EPSS Percentile 99.5%

Details

Status published
Products (25)
php/php 5.5.0 (13 CPE variants)
php/php 5.5.1
php/php 5.5.2
php/php 5.5.3
php/php 5.5.4
php/php 5.5.5
php/php 5.5.6
php/php 5.5.7
php/php 5.5.8
php/php 5.5.9
... and 15 more
Published Dec 20, 2014
Tracked Since Feb 18, 2026