CVE-2015-6831

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
19/01/2016
Last modified:
12/04/2025

Description

Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.4.44 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.28 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.12 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*