Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2301
Reference (s):
- APPLE:APPLE-SA-2015-09-30-3
- URL: http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- BID:73037
- URL: http://www.securityfocus.com/bid/73037
- http://git.php.net/?p=php-src.git;a=commit;h=b2cf3f064b8f5efef89bb084521b61318c71781b