Description
ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2014-0452 Vulnerability (CVE-2014-0452)
Moodle 7PK - Security Features Vulnerability (CVE-2015-5331)
WordPress Plugin Responsive WordPress Slider Cross-Site Scripting (2.2.0)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3546)
WordPress Plugin Redirection 'id' Parameter Cross-Site Scripting (2.2.8)