PHP 5.6.9 Use-After-Free

Discussion in 'News Aggregator' started by Packet Storm, 10 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    High-Tech Bridge Security Research Lab discovered use-after-free vulnerability in a popular programming language PHP, which can be exploited to cause crash and possibly execute arbitrary code on the target system. The vulnerability resides within the 'spl_heap_object_free_storage()' PHP function when trying to dereference already freed memory. A local attacker can cause segmentation fault or possibly execute arbitrary code on the target system with privileges of webserver.

    Continue reading...
     

Share This Page

Loading...