CVE-2016-3132

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-3132
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-3132.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-3132
Downstream
Published
2016-08-07T10:59:04Z
Modified
2025-09-19T08:19:24.254328Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

NEWS
NEWS-cvs2svn
POST_64BIT_BRANCH_MERGE
POST_AST_MERGE
POST_NATIVE_TLS_MERGE
POST_PHP7_EREG_MYSQL_REMOVALS
POST_PHP7_NSAPI_REMOVAL
POST_PHP7_REMOVALS
POST_PHPNG_MERGE
PRE_64BIT_BRANCH_MERGE
PRE_AST_MERGE
PRE_NATIVE_TLS_MERGE
PRE_PHP7_EREG_MYSQL_REMOVALS
PRE_PHP7_NSAPI_REMOVAL
PRE_PHP7_REMOVALS
PRE_PHPNG_MERGE

php-5.*

php-5.3.23RC1
php-5.3.29
php-5.3.29RC1
php-5.4.30RC1
php-5.4.32RC1
php-5.4.4RC2
php-5.5.24RC1
php-5.6.18RC1
php-5.6.19RC1

php-7.*

php-7.0.3RC1
php-7.0.4RC1

Database specific

{
    "vanir_signatures": [
        {
            "source": "https://github.com/php/php-src/commit/28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5",
            "signature_version": "v1",
            "signature_type": "Line",
            "id": "CVE-2016-3132-80891d30",
            "target": {
                "file": "ext/spl/spl_dllist.c"
            },
            "digest": {
                "line_hashes": [
                    "319179387729034841274760469604206168445",
                    "48832863698665694236481967152139719407",
                    "59111686446782427339145098948808976296",
                    "261215441993593876712539833676253033257"
                ],
                "threshold": 0.9
            },
            "deprecated": false
        },
        {
            "source": "https://github.com/php/php-src/commit/28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5",
            "signature_version": "v1",
            "signature_type": "Function",
            "id": "CVE-2016-3132-89df2204",
            "target": {
                "file": "ext/spl/spl_dllist.c",
                "function": "SPL_METHOD"
            },
            "digest": {
                "function_hash": "1131720695874403450086703265789160689",
                "length": 864.0
            },
            "deprecated": false
        }
    ]
}