Vulnerabilities > CVE-2014-3622 - Use After Free vulnerability in PHP 5.6.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
php
CWE-416
critical
nessus

Summary

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

Vulnerable Configurations

Part Description Count
Application
Php
15

Common Weakness Enumeration (CWE)

Nessus

NASL familyCGI abuses
NASL idPHP_5_6_1.NASL
descriptionAccording to its banner, the version of PHP 5.6.x installed on the remote host is prior to 5.6.1. It is, therefore, affected by errors related to the function
last seen2020-06-01
modified2020-06-02
plugin id78082
published2014-10-07
reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/78082
titlePHP 5.6.x < 5.6.1 'add_post_var' Code Execution