SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  PHP SPL Component Memory Corruption

Category: PL-VULNS      

The SPL component in PHP incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3515


Relevant Information