CVE-2014-8142

high
Published 2014-12-20 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.php.net/bug.php?id=68594

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://php.net/ChangeLog-5.php

Application impact

VendorProductVersionsFixed
php phpphp{"endIncluding":"5.4.35"}
php phpphp5.5.0
php phpphp5.5.1
php phpphp5.5.2
php phpphp5.5.3
php phpphp5.5.4
php phpphp5.5.5
php phpphp5.5.6
php phpphp5.5.7
php phpphp5.5.8
php phpphp5.5.9
php phpphp5.5.10
php phpphp5.5.11
php phpphp5.5.12
php phpphp5.5.13
php phpphp5.5.14
php phpphp5.5.15
php phpphp5.5.16
php phpphp5.5.17
php phpphp5.5.18
php phpphp5.5.19
php phpphp5.6.0
php phpphp5.6.1
php phpphp5.6.2
php phpphp5.6.3

References

Verify integrity in audit chain (admin only). AS-IS.