CVE-2014-9425
published 2014-12-31CVE-2014-9425: Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.66%
88.4th percentile
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.5 | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| php | php | <= 5.5.20 | — |
| php | php | 5.6.0 – 5.6.4 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j29m-6pgw-53qh: Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash
ghsa_unreviewed·2022-05-14
CVE-2014-9425 [HIGH] GHSA-j29m-6pgw-53qh: Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Red Hat
php: Double-free in zend_ts_hash_graceful_destroy()
vendor_redhat·2014-12-30·CVSS 7.5
CVE-2014-9425 [HIGH] CWE-416 php: Double-free in zend_ts_hash_graceful_destroy()
php: Double-free in zend_ts_hash_graceful_destroy()
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
A double free flaw was found in zend_ts_hash_graceful_destroy() function in the PHP ZTS module. This flaw could possibly cause a PHP application to crash.
Statement: This issue did not affect the versions of php and php53 as shipped with Red Hat Enterprise Linux 5, and the versions of php as shipped with Red Hat Enterprise Linux 7.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat
Apple
CVE-2014-9425: OS X El Capitan v10.11
vendor_apple·CVSS 7.5
CVE-2014-9425 [HIGH] CVE-2014-9425: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2014-9425
Component: CVE-2014-9425
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy() [fedora-all]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9425 [HIGH] CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy() [fedora-all]
CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy()
bugzilla·2014-12-30·CVSS 7.5
CVE-2014-9425 [HIGH] CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy()
CVE-2014-9425 php: Double-free in zend_ts_hash_graceful_destroy()
A double-free flaw was found in PHP in the zend_ts_hash_graceful_destroy() function. This issue affects all versions of PHP. Initial investigations suggests that it may not be exploitable and can only result in a crash.
References:
Upstream bug: https://bugs.php.net/bug.php?id=68676
Commits:
http://git.php.net/?p=php-src.git;a=commit;h=2bcf69d073190e4f032d883f3416dea1b027a39e
http://git.php.net/?p=php-src.git;a=commit;h=24125f0f26f3787c006e4a51611ba33ee3b841cb
http://git.php.net/?p=php-src.git;a=commit;h=fbf3a6bc1abcc8a5b5226b0ad9464c37f11ddbd6
Discussion:
As this code is ZTS specific, it only affects ZTS enabled build.
(in RHEL, only php/rhel-6 have ZTS build, provided as experimental)
---
(In reply to Remi Collet f
http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=24125f0f26f3787c006e4a51611ba33ee3b841cbhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=2bcf69d073190e4f032d883f3416dea1b027a39ehttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=fbf3a6bc1abcc8a5b5226b0ad9464c37f11ddbd6http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://openwall.com/lists/oss-security/2014/12/29/6http://rhn.redhat.com/errata/RHSA-2015-1218.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/71800https://bugs.php.net/bug.php?id=68676https://security.gentoo.org/glsa/201503-03https://support.apple.com/HT205267http://advisories.mageia.org/MGASA-2015-0040.htmlhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=24125f0f26f3787c006e4a51611ba33ee3b841cbhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=2bcf69d073190e4f032d883f3416dea1b027a39ehttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=fbf3a6bc1abcc8a5b5226b0ad9464c37f11ddbd6http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://openwall.com/lists/oss-security/2014/12/29/6http://rhn.redhat.com/errata/RHSA-2015-1218.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/71800https://bugs.php.net/bug.php?id=68676https://security.gentoo.org/glsa/201503-03https://support.apple.com/HT205267
2014-12-31
Published