Vulnerabilities > CVE-2014-3622 - Use After Free vulnerability in PHP 5.6.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
php
CWE-416
nessus

Summary

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

Vulnerable Configurations

Part Description Count
Application
Php
15

Common Weakness Enumeration (CWE)

Nessus

NASL familyCGI abuses
NASL idPHP_5_6_1.NASL
descriptionAccording to its banner, the version of PHP 5.6.x installed on the remote host is prior to 5.6.1. It is, therefore, affected by errors related to the function
last seen2020-06-01
modified2020-06-02
plugin id78082
published2014-10-07
reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/78082
titlePHP 5.6.x < 5.6.1 'add_post_var' Code Execution