PHP Use After Free Vulnerability - CVE-2016-6290 - Vulnerability Database

PHP Use After Free Vulnerability - CVE-2016-6290

Critical
Reference: CVE-2016-6290
Title: PHP Use After Free Vulnerability
Overview:

ext/session/session.c in PHP before 5.5.38 5.6.x before 5.6.24 and 7.x before 7.0.9 does not properly maintain a certain hash data structure which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.