PHP 5.6 / 5.5 / 5.4 unserialize() Use-After-Free

Discussion in 'News Aggregator' started by Packet Storm, 9 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    Multiple use-after-free vulnerabilities were discovered in unserialize() with Serializable class that can be abused for leaking arbitrary memory blocks or for executing arbitrary code remotely. Affected are PHP versions 5.6.12 and below, 5.5.28 and below, and 5.4.44 and below.

    Continue reading...
     

Share This Page

Loading...