CVE-2015-6831
published 2016-01-19CVE-2015-6831: Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary…
PriorityP351high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
7.06%
93.5th percentile
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | < 5.4.44 | 5.4.44 |
| php | php | >= 5.5.0 < 5.5.28 | 5.5.28 |
| php | php | >= 5.6.0 < 5.6.12 | 5.6.12 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.13 | 5.5.9+dfsg-1ubuntu4.13 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2015-09-30·CVSS 9.8
CVE-2015-5589 [CRITICAL] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that the PHP phar extension incorrectly handled certain
files. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service. (CVE-2015-5589)
It was discovered that the PHP phar extension incorrectly handled certain
filepaths. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-5590)
Taoguang Chen discovered that PHP incorrectly handled unserializing
objects. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-6831, CVE-2015-6834, CVE-2015-6835
Sean Heelan discovered that PHP inco
Red Hat
php: Use After Free Vulnerability in unserialize()
vendor_redhat·2015-08-06·CVSS 7.3
CVE-2015-6831 [HIGH] CWE-416 php: Use After Free Vulnerability in unserialize()
php: Use After Free Vulnerability in unserialize()
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.
A flaw was discovered in the way PHP performed object unserialization. Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Pa
GHSA
GHSA-44m9-gpqm-x8fj: Multiple use-after-free vulnerabilities in SPL in PHP before 5
ghsa_unreviewed·2022-05-17
CVE-2015-6831 [HIGH] CWE-416 GHSA-44m9-gpqm-x8fj: Multiple use-after-free vulnerabilities in SPL in PHP before 5
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.
OSV
php5 vulnerabilities
osv·2015-09-30·CVSS 9.8
CVE-2015-5589 [CRITICAL] php5 vulnerabilities
php5 vulnerabilities
It was discovered that the PHP phar extension incorrectly handled certain
files. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service. (CVE-2015-5589)
It was discovered that the PHP phar extension incorrectly handled certain
filepaths. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-5590)
Taoguang Chen discovered that PHP incorrectly handled unserializing
objects. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-6831, CVE-2015-6834, CVE-2015-6835
Sean Heelan discovered that PHP incorrectly handled unserializing
objects. A remote attacker co
OSV
CVE-2015-6831: Multiple use-after-free vulnerabilities in SPL in PHP before 5
osv·2015-08-27·CVSS 7.3
CVE-2015-6831 [HIGH] CVE-2015-6831: Multiple use-after-free vulnerabilities in SPL in PHP before 5
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2015/dsa-3344http://www.openwall.com/lists/oss-security/2015/08/19/3http://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/76737https://bugs.php.net/bug.php?id=70155https://bugs.php.net/bug.php?id=70166https://bugs.php.net/bug.php?id=70168https://bugs.php.net/bug.php?id=70169https://security.gentoo.org/glsa/201606-10http://www.debian.org/security/2015/dsa-3344http://www.openwall.com/lists/oss-security/2015/08/19/3http://www.php.net/ChangeLog-5.phphttp://www.securityfocus.com/bid/76737https://bugs.php.net/bug.php?id=70155https://bugs.php.net/bug.php?id=70166https://bugs.php.net/bug.php?id=70168https://bugs.php.net/bug.php?id=70169https://security.gentoo.org/glsa/201606-10
2016-01-19
Published