Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19308
HistoryMay 16, 2019 - 2:59 a.m.

Use-After-Free

2019-05-1602:59:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.01 Low

EPSS

Percentile

83.7%

PHP is vulnerable to use-after-free vulnerability. This is because the ext/standard/var_unserializer.re in PHP is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. This could impact the integrity of PHP.