PHP 5.6 / 5.5 / 5.4...

- AV AC AU C I A
发布: 2015-09-07
修订: 2025-04-13

A use-after-free vulnerability was discovered in unserialize() with SplDoublyLinkedList object's deserialization and crafted object's __wakeup() magic method that can be abused for leaking arbitrary memory blocks or executing arbitrary code remotely. Affected are PHP versions 5.6.12 and below, 5.5.28 and below, and 5.4.44 and below.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息