php.netConfirmation
http://php.net/ChangeLog-5.php CVE-2015-6834
CRITICAL
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
Record summary
CVE-2015-6834 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits.
Description
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBPHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-FreeExploitDB exploitby Taoguang ChenNot analyzed1 file
ExploitDBPHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-FreeExploitDB exploitby Taoguang ChenNot analyzed1 file
References
9DSA-3358Vendor advisory
http://www.debian.org/security/2015/dsa-3358 76649vdb entry
http://www.securityfocus.com/bid/76649 1033548vdb entry
http://www.securitytracker.com/id/1033548 bugs.php.netConfirmation
https://bugs.php.net/bug.php?id=70172 bugs.php.netConfirmation
https://bugs.php.net/bug.php?id=70365 bugs.php.netConfirmation
https://bugs.php.net/bug.php?id=70366 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-6834 GLSA-201606-10Vendor advisory
https://security.gentoo.org/glsa/201606-10