CVE Vulnerabilities

CVE-2010-2225

Published: Jun 24, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.2.0 (including)5.2.0 (including)
PhpPhp5.2.1 (including)5.2.1 (including)
PhpPhp5.2.2 (including)5.2.2 (including)
PhpPhp5.2.3 (including)5.2.3 (including)
PhpPhp5.2.4 (including)5.2.4 (including)
PhpPhp5.2.5 (including)5.2.5 (including)
PhpPhp5.2.6 (including)5.2.6 (including)
PhpPhp5.2.7 (including)5.2.7 (including)
PhpPhp5.2.8 (including)5.2.8 (including)
PhpPhp5.2.9 (including)5.2.9 (including)
PhpPhp5.2.10 (including)5.2.10 (including)
PhpPhp5.2.11 (including)5.2.11 (including)
PhpPhp5.2.12 (including)5.2.12 (including)
PhpPhp5.2.13 (including)5.2.13 (including)
Php5Ubuntuhardy*
Php5Ubuntujaunty*
Php5Ubuntukarmic*
Php5Ubuntulucid*
Php5Ubuntuupstream*

References