Yet Another Use After Free Vulnerability in unserialize() with SplObjectStorage

Posted by Taoguang Chen on Sep 07

#Yet Another Use After Free Vulnerability in unserialize() with SplObjectStorage

Taoguang Chen <[@chtg](http://github.com/chtg)> – Write Date:
2015.8.27 – Release Date: 2015.9.4

Affected Versions
————
Affected is PHP 5.6 < 5.6.13
Affected is PHP 5.5 < 5.5.29
Affected is PHP 5.4 < 5.4.45

Credits
————
This vulnerability was disclosed by Taoguang Chen.

Description
————

“`…

Leave a Reply