Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
[
{
"digest": {
"line_hashes": [
"319179387729034841274760469604206168445",
"48832863698665694236481967152139719407",
"59111686446782427339145098948808976296",
"261215441993593876712539833676253033257"
],
"threshold": 0.9
},
"id": "CVE-2016-3132-80891d30",
"target": {
"file": "ext/spl/spl_dllist.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/php/php-src/commit/28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "1131720695874403450086703265789160689",
"length": 864.0
},
"id": "CVE-2016-3132-89df2204",
"target": {
"function": "SPL_METHOD",
"file": "ext/spl/spl_dllist.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/php/php-src/commit/28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5",
"signature_type": "Function"
}
]