CVE-2016-5773 is a critical use-after-free vulnerability in the php_zip.c component of the PHP zip extension, affecting versions before 5.5.37, 5.6.23, and 7.0.8. This flaw arises from improper interaction between the zip extension, PHP's unserialize implementation, and garbage collection. Attackers can exploit this by sending specially crafted serialized data containing a ZipArchive object. The vulnerability carries a CVSS v3 score of 9.8 (Critical), indicating a severe risk. It allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (application crash) with low attack complexity. The potential impact includes complete compromise of confidentiality, integrity, and availability. While there is no publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion with 11 mentions and was reportedly used in real-world attacks against PornHub, as highlighted by SecurityWeek. Despite its age, its high FAUCET Risk Score and past exploitation suggest continued relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.5.36CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:* | ||
5.6.0CPE matchmatch criteria | cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.