← Back

CVE-2016-7479

nvd nist
Published: Jan 12, 2017Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

Affected (15)

Products: Php: Php
1 product
Php
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 7.0.0
Version 7.0.10
Version 7.0.11
Version 7.0.12
Version 7.0.14
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0.7
Version 7.0.8
Version 7.0.9
Version 7.1.0

References (16)

Source: cve@checkpoint.com
ExploitTechnical DescriptionThird Party Advisory
Source: cve@checkpoint.com
Third Party AdvisoryVDB Entry
Source: cve@checkpoint.com
Issue TrackingPermissions Required
Source: cve@checkpoint.com
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description

Timeline

No history available yet.