PT-2020-6652 · Php · Php

Vasyl Kaigorodov

·

Published

2020-02-19

·

Updated

2024-06-15

·

CVE-2014-3622

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions 5.6.x through 5.6.0
Description The issue is related to a use-after-free vulnerability in the add post var function of the Posthandler component. This vulnerability can be exploited by remote attackers to execute arbitrary PHP code by leveraging a third-party filter extension that accesses a certain ksep value.
Recommendations For PHP versions 5.6.x through 5.6.0, update to version 5.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to third-party filter extensions that may access the ksep value until a patch is applied.

Exploit

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02641
CVE-2014-3622
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1

Affected Products

Php