Description
Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging the relationships between a key buffer and a destroyed array.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-5844 Vulnerability (CVE-2013-5844)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2272)
GeoServer Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2025-30145)
WordPress Plugin WP SimpleMail Multiple Cross-Site Scripting Vulnerabilities (1.0.6)