CVE Vulnerabilities

CVE-2015-6832

Published: Jan 19, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers misuse of an array field.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp*5.4.43 (including)
PhpPhp5.5.0 (including)5.5.0 (including)
PhpPhp5.5.0-alpha1 (including)5.5.0-alpha1 (including)
PhpPhp5.5.0-alpha2 (including)5.5.0-alpha2 (including)
PhpPhp5.5.0-alpha3 (including)5.5.0-alpha3 (including)
PhpPhp5.5.0-alpha4 (including)5.5.0-alpha4 (including)
PhpPhp5.5.0-alpha5 (including)5.5.0-alpha5 (including)
PhpPhp5.5.0-alpha6 (including)5.5.0-alpha6 (including)
PhpPhp5.5.0-beta1 (including)5.5.0-beta1 (including)
PhpPhp5.5.0-beta2 (including)5.5.0-beta2 (including)
PhpPhp5.5.0-beta3 (including)5.5.0-beta3 (including)
PhpPhp5.5.0-beta4 (including)5.5.0-beta4 (including)
PhpPhp5.5.0-rc1 (including)5.5.0-rc1 (including)
PhpPhp5.5.0-rc2 (including)5.5.0-rc2 (including)
PhpPhp5.5.1 (including)5.5.1 (including)
PhpPhp5.5.2 (including)5.5.2 (including)
PhpPhp5.5.3 (including)5.5.3 (including)
PhpPhp5.5.4 (including)5.5.4 (including)
PhpPhp5.5.5 (including)5.5.5 (including)
PhpPhp5.5.6 (including)5.5.6 (including)
PhpPhp5.5.7 (including)5.5.7 (including)
PhpPhp5.5.8 (including)5.5.8 (including)
PhpPhp5.5.9 (including)5.5.9 (including)
PhpPhp5.5.10 (including)5.5.10 (including)
PhpPhp5.5.11 (including)5.5.11 (including)
PhpPhp5.5.12 (including)5.5.12 (including)
PhpPhp5.5.13 (including)5.5.13 (including)
PhpPhp5.5.14 (including)5.5.14 (including)
PhpPhp5.5.18 (including)5.5.18 (including)
PhpPhp5.5.19 (including)5.5.19 (including)
PhpPhp5.5.20 (including)5.5.20 (including)
PhpPhp5.5.21 (including)5.5.21 (including)
PhpPhp5.5.22 (including)5.5.22 (including)
PhpPhp5.5.23 (including)5.5.23 (including)
PhpPhp5.5.24 (including)5.5.24 (including)
PhpPhp5.5.25 (including)5.5.25 (including)
PhpPhp5.5.26 (including)5.5.26 (including)
PhpPhp5.5.27 (including)5.5.27 (including)
PhpPhp5.6.0-alpha1 (including)5.6.0-alpha1 (including)
PhpPhp5.6.0-alpha2 (including)5.6.0-alpha2 (including)
PhpPhp5.6.0-alpha3 (including)5.6.0-alpha3 (including)
PhpPhp5.6.0-alpha4 (including)5.6.0-alpha4 (including)
PhpPhp5.6.0-alpha5 (including)5.6.0-alpha5 (including)
PhpPhp5.6.0-beta1 (including)5.6.0-beta1 (including)
PhpPhp5.6.0-beta2 (including)5.6.0-beta2 (including)
PhpPhp5.6.0-beta3 (including)5.6.0-beta3 (including)
PhpPhp5.6.0-beta4 (including)5.6.0-beta4 (including)
PhpPhp5.6.1 (including)5.6.1 (including)
PhpPhp5.6.2 (including)5.6.2 (including)
PhpPhp5.6.3 (including)5.6.3 (including)
PhpPhp5.6.4 (including)5.6.4 (including)
PhpPhp5.6.5 (including)5.6.5 (including)
PhpPhp5.6.6 (including)5.6.6 (including)
PhpPhp5.6.7 (including)5.6.7 (including)
PhpPhp5.6.8 (including)5.6.8 (including)
PhpPhp5.6.9 (including)5.6.9 (including)
PhpPhp5.6.10 (including)5.6.10 (including)
PhpPhp5.6.11 (including)5.6.11 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-php56-php-0:5.6.5-8.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php56-php-0:5.6.5-8.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-php56-php-0:5.6.5-8.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-php56-php-0:5.6.5-8.el7*
Php5Ubuntudevel*
Php5Ubuntuesm-infra-legacy/trusty*
Php5Ubuntuprecise*
Php5Ubuntutrusty*
Php5Ubuntutrusty/esm*
Php5Ubuntuupstream*
Php5Ubuntuvivid*

References