CVE-2016-5771 is a critical use-after-free vulnerability in the SPL extension of PHP versions prior to 5.5.37 and 5.6.23, affecting products like Debian and openSUSE. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through crafted serialized data due to improper interaction with the unserialize implementation and garbage collection. Rated with a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector with no user interaction required, leading to high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is listed, the vulnerability has garnered significant media attention, including a report of its use in attacks against PornHub, indicating a history of real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.37CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.6.0, < 5.6.23CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.8CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.