CVE-2016-3132: Double Free
Published Aug 7, 2016
·Updated
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spldllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
Affected Software
7 affected components
debian/php7.0
PHP PHP=7.0.0
PHP PHP=7.0.1
PHP PHP=7.0.2
PHP PHP=7.0.3
PHP PHP=7.0.4
PHP PHP=7.0.5
Remediation
Patch Available
Event History
Aug 7, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:17 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:14 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2016-3132?
CVE-2016-3132 is a double free vulnerability in the SplDoublyLinkedList::offsetSet function in PHP 7.x before 7.0.6.
2
How does CVE-2016-3132 impact PHP?
CVE-2016-3132 allows remote attackers to execute arbitrary code via a crafted index.
3
What is the severity of CVE-2016-3132?
CVE-2016-3132 has a severity rating of 9.8 (critical).
4
Which versions of PHP are affected by CVE-2016-3132?
PHP versions 7.0.0 to 7.0.5 are affected by CVE-2016-3132.
5
How can I fix CVE-2016-3132?
To fix CVE-2016-3132, upgrade to PHP version 7.0.6 or later.