CVE Vulnerabilities

CVE-2016-5768

Double Free

Published: Aug 07, 2016 | Modified: Jan 05, 2018
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.5.36 (including)
Php Php 5.6.0-alpha1 (including) 5.6.0-alpha1 (including)
Php Php 5.6.0-alpha2 (including) 5.6.0-alpha2 (including)
Php Php 5.6.0-alpha3 (including) 5.6.0-alpha3 (including)
Php Php 5.6.0-alpha4 (including) 5.6.0-alpha4 (including)
Php Php 5.6.0-alpha5 (including) 5.6.0-alpha5 (including)
Php Php 5.6.0-beta1 (including) 5.6.0-beta1 (including)
Php Php 5.6.0-beta2 (including) 5.6.0-beta2 (including)
Php Php 5.6.0-beta3 (including) 5.6.0-beta3 (including)
Php Php 5.6.0-beta4 (including) 5.6.0-beta4 (including)
Php Php 5.6.1 (including) 5.6.1 (including)
Php Php 5.6.2 (including) 5.6.2 (including)
Php Php 5.6.3 (including) 5.6.3 (including)
Php Php 5.6.4 (including) 5.6.4 (including)
Php Php 5.6.5 (including) 5.6.5 (including)
Php Php 5.6.6 (including) 5.6.6 (including)
Php Php 5.6.7 (including) 5.6.7 (including)
Php Php 5.6.8 (including) 5.6.8 (including)
Php Php 5.6.9 (including) 5.6.9 (including)
Php Php 5.6.10 (including) 5.6.10 (including)
Php Php 5.6.11 (including) 5.6.11 (including)
Php Php 5.6.12 (including) 5.6.12 (including)
Php Php 5.6.13 (including) 5.6.13 (including)
Php Php 5.6.14 (including) 5.6.14 (including)
Php Php 5.6.15 (including) 5.6.15 (including)
Php Php 5.6.16 (including) 5.6.16 (including)
Php Php 5.6.17 (including) 5.6.17 (including)
Php Php 5.6.18 (including) 5.6.18 (including)
Php Php 5.6.19 (including) 5.6.19 (including)
Php Php 5.6.20 (including) 5.6.20 (including)
Php Php 5.6.21 (including) 5.6.21 (including)
Php Php 5.6.22 (including) 5.6.22 (including)
Php Php 7.0.0 (including) 7.0.0 (including)
Php Php 7.0.1 (including) 7.0.1 (including)
Php Php 7.0.2 (including) 7.0.2 (including)
Php Php 7.0.3 (including) 7.0.3 (including)
Php Php 7.0.4 (including) 7.0.4 (including)
Php Php 7.0.5 (including) 7.0.5 (including)
Php Php 7.0.6 (including) 7.0.6 (including)
Php Php 7.0.7 (including) 7.0.7 (including)

Potential Mitigations

References