Back
CVE-2015-4116
CRITICAL
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.
Published: May 16, 2016
Modified: Jun 17, 2026
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (13)
| Vendor | Product | Version |
|---|---|---|
| opensuse | leap | 42.1 |
| php | php | * |
| php | php | 5.6.0 |
| php | php | 5.6.1 |
| php | php | 5.6.2 |
| php | php | 5.6.3 |
| php | php | 5.6.4 |
| php | php | 5.6.5 |
| php | php | 5.6.6 |
| php | php | 5.6.7 |
| php | php | 5.6.8 |
| php | php | 5.6.9 |
| php | php | 5.6.10 |
GitHub Security Advisory GHSA-6648-4fcr-v6ch
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP...
References (10)
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1cbd25ca15383394ffa9ee8601c5de4c0f2f90e1
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00027.html
- http://php.net/ChangeLog-5.php
- https://bugs.php.net/bug.php?id=69737 Exploit
- https://www.htbridge.com/advisory/HTB23262 Exploit
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=1cbd25ca15383394ffa9ee8601c5de4c0f2f90e1
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00027.html
- http://php.net/ChangeLog-5.php
- https://bugs.php.net/bug.php?id=69737 Exploit
- https://www.htbridge.com/advisory/HTB23262 Exploit
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
5.47%
Top 8% most likely to be exploited
Threat Score
40.8 / 100
Data Sources
NVD
EPSS
GitHub