CVE-2010-4697: Use After Free
Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of set, get, isset, and unset methods on objects accessed by a reference.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4697?
CVE-2010-4697 is classified as a moderate severity vulnerability due to its potential for denial of service and memory corruption.
How do I fix CVE-2010-4697?
To fix CVE-2010-4697, upgrade your PHP installation to version 5.2.15 or 5.3.4 or later.
What software versions are affected by CVE-2010-4697?
CVE-2010-4697 affects PHP versions prior to 5.2.15 and 5.3.4, including various earlier versions such as 4.3.x and 5.1.x.
What are the potential impacts of CVE-2010-4697?
The potential impacts of CVE-2010-4697 include denial of service due to heap memory corruption and possibly other unspecified effects.
Is there a workaround for CVE-2010-4697?
There are no specific workarounds for CVE-2010-4697 other than upgrading to the fixed versions.