CVE-2015-1351: Apple Mac OS X
High severity, CVSS 7.5. EPSS: 8.6% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected products
- Apple Mac OS X: up to and including 10.6.8
- Oracle Linux: version 6 only; version 7 only
- Oracle Secure Backup: up to and including 12.1.0.1.0
- Oracle Solaris: version 11.2 only
- PHP PHP: before 5.5.24 (fixed in 5.5.24); from 5.6.0, before 5.6.8 (fixed in 5.6.8)
Published 2015-03-30. Last modified 2026-06-17.