Description
The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Post Type UI Cross-Site Request Forgery (1.7.3)
WordPress Plugin LearnDash LMS SQL Injection (4.5.3)
WordPress Plugin Multiplayer Games Cross-Site Scripting (3.7)
Moodle Uncontrolled Resource Consumption Vulnerability (CVE-2020-25630)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9514)