// For flags

CVE-2015-0231

php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142)

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.

Vulnerabilidad del uso después de liberación en la función process_nested_data en ext/standard/var_unserializer.re en PHP anterior a 5.4.37, 5.5.x anterior a 5.5.21, y 5.6.x anterior a 5.6.5 permite a atacantes remotos ejecutar código arbitrario a través de una llamada de no serializar manipulada que aprovecha el manejo incorrecto de claves numéricas duplicadas dentro de las propiedades serializadas de un objeto. NOTA: este vulnerabilidad existe debido a una solución incompleta para CVE-2014-8142.

A use-after-free flaw was found in the way PHP's unserialize() function processed data. If a remote attacker was able to pass crafted input to PHP's unserialize() function, they could cause the PHP interpreter to crash or, possibly, execute arbitrary code.

S. Paraschoudis discovered that PHP incorrectly handled memory in the enchant binding. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. Taoguang Chen discovered that PHP incorrectly handled unserializing objects. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that PHP incorrectly handled memory in the phar extension. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way libzip, which is embedded in PHP, processed certain ZIP archives. If an attacker were able to supply a specially crafted ZIP archive to an application using libzip, it could cause the application to crash or, possibly, execute arbitrary code. It was discovered that the PHP opcache component incorrectly handled memory. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that the PHP PostgreSQL database extension incorrectly handled certain pointers. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. The updated php packages have been patched and upgraded to the 5.5.23 version which is not vulnerable to these issues. The libzip packages has been patched to address the flaw. Additionally the php-xdebug package has been upgraded to the latest 2.3.2 and the PECL packages which requires so has been rebuilt for php-5.5.23.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-11-18 CVE Reserved
  • 2015-01-27 CVE Published
  • 2023-04-01 First Exploit
  • 2024-08-06 CVE Updated
  • 2025-08-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-416: Use After Free
CAPEC
References (25)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.4.36
Search vendor "Php" for product "Php" and version " <= 5.4.36"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.0
Search vendor "Php" for product "Php" and version "5.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.1
Search vendor "Php" for product "Php" and version "5.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.2
Search vendor "Php" for product "Php" and version "5.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.3
Search vendor "Php" for product "Php" and version "5.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.4
Search vendor "Php" for product "Php" and version "5.4.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.5
Search vendor "Php" for product "Php" and version "5.4.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.6
Search vendor "Php" for product "Php" and version "5.4.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.7
Search vendor "Php" for product "Php" and version "5.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.8
Search vendor "Php" for product "Php" and version "5.4.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.9
Search vendor "Php" for product "Php" and version "5.4.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.10
Search vendor "Php" for product "Php" and version "5.4.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.11
Search vendor "Php" for product "Php" and version "5.4.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.15
Search vendor "Php" for product "Php" and version "5.4.15"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.16
Search vendor "Php" for product "Php" and version "5.4.16"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.17
Search vendor "Php" for product "Php" and version "5.4.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.18
Search vendor "Php" for product "Php" and version "5.4.18"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.19
Search vendor "Php" for product "Php" and version "5.4.19"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.20
Search vendor "Php" for product "Php" and version "5.4.20"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.21
Search vendor "Php" for product "Php" and version "5.4.21"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.22
Search vendor "Php" for product "Php" and version "5.4.22"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.23
Search vendor "Php" for product "Php" and version "5.4.23"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.24
Search vendor "Php" for product "Php" and version "5.4.24"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.25
Search vendor "Php" for product "Php" and version "5.4.25"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.26
Search vendor "Php" for product "Php" and version "5.4.26"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.27
Search vendor "Php" for product "Php" and version "5.4.27"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.28
Search vendor "Php" for product "Php" and version "5.4.28"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.29
Search vendor "Php" for product "Php" and version "5.4.29"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.30
Search vendor "Php" for product "Php" and version "5.4.30"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.34
Search vendor "Php" for product "Php" and version "5.4.34"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.35
Search vendor "Php" for product "Php" and version "5.4.35"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha5
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha6
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.1
Search vendor "Php" for product "Php" and version "5.5.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.2
Search vendor "Php" for product "Php" and version "5.5.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.3
Search vendor "Php" for product "Php" and version "5.5.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.4
Search vendor "Php" for product "Php" and version "5.5.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.5
Search vendor "Php" for product "Php" and version "5.5.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.6
Search vendor "Php" for product "Php" and version "5.5.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.7
Search vendor "Php" for product "Php" and version "5.5.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.8
Search vendor "Php" for product "Php" and version "5.5.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.9
Search vendor "Php" for product "Php" and version "5.5.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.10
Search vendor "Php" for product "Php" and version "5.5.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.11
Search vendor "Php" for product "Php" and version "5.5.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.12
Search vendor "Php" for product "Php" and version "5.5.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.13
Search vendor "Php" for product "Php" and version "5.5.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.14
Search vendor "Php" for product "Php" and version "5.5.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.15
Search vendor "Php" for product "Php" and version "5.5.15"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.16
Search vendor "Php" for product "Php" and version "5.5.16"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.17
Search vendor "Php" for product "Php" and version "5.5.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.18
Search vendor "Php" for product "Php" and version "5.5.18"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.19
Search vendor "Php" for product "Php" and version "5.5.19"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.20
Search vendor "Php" for product "Php" and version "5.5.20"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
alpha1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
alpha2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
alpha3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
alpha4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
alpha5
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.0
Search vendor "Php" for product "Php" and version "5.6.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.1
Search vendor "Php" for product "Php" and version "5.6.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.2
Search vendor "Php" for product "Php" and version "5.6.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.3
Search vendor "Php" for product "Php" and version "5.6.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.6.4
Search vendor "Php" for product "Php" and version "5.6.4"
-
Affected