CVE-2015-6834
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 47%
from disclosure to weapon0 days
Published on NVDMay 16
1st PoCSep 9
exploitation probability
47%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38120exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38122⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://php.net/ChangeLog-5.phphttps://bugs.php.net/bug.php?id=70172https://bugs.php.net/bug.php?id=70365https://bugs.php.net/bug.php?id=70366https://security.gentoo.org/glsa/201606-10http://www.debian.org/security/2015/dsa-3358http://www.securityfocus.com/bid/76649http://www.securitytracker.com/id/1033548