Severity
10.0CRITICAL
EPSS
6.8%
top 8.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDphp/php49 versions+48
NVDopenpkg/openpkg2.1, 2.2, current+2
NVDtrustix/secure_linux2.0, 2.1, 2.2+2

Also affects: Ubuntu Linux 4.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8xg9-g9f5-rcr7: The deserialization code in PHP before 42022-04-29
CVEList
CVE-2004-1019: The deserialization code in PHP before 42004-12-22

📋Vendor Advisories

3
Red Hat
php: use after free vulnerability in unserialize()2014-12-18
Ubuntu
PHP vulnerabilities2004-12-17
Red Hat
security flaw2004-12-15

💬Community

2
Bugzilla
CVE-2004-1019 security flaw2018-08-16
Bugzilla
CVE-2004-0595 PHP flaws (CVE-2004-0594 CVE-2004-1018 CVE-2004-1019)2005-10-25