In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-875-1 | php5 security update |
Ubuntu USN |
USN-3196-1 | PHP vulnerabilities |
Ubuntu USN |
USN-3211-1 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: checkpoint
Published:
Updated: 2024-08-06T01:57:47.655Z
Reserved: 2016-09-09T00:00:00
Link: CVE-2016-7479
No data.
Status : Deferred
Published: 2017-01-12T00:59:00.140
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-7479
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN