Use After Free Vulnerability in unserialize() with DateInterval

Posted by Taoguang Chen on Mar 20

#Use After Free Vulnerability in unserialize() with DateInterval

Taoguang Chen <[ () chtg](http://github.com/chtg)> – Write Date:
2015.2.28 – Release Date: 2015.3.20

Affected Versions
————
Affected is PHP 5.6 < 5.6.7
Affected is PHP 5.5 < 5.5.23
Affected is PHP 5.4 < 5.4.39
Affected is PHP 5.3 <= 5.3.29

Credits
————
This vulnerability was disclosed by Taoguang Chen.

Description
————

“`
static int…

Leave a Reply