CVE-2015-1351: Apple Mac OS X

High severity, CVSS 7.5. EPSS: 8.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Affected products

  • Apple Mac OS X: up to and including 10.6.8
  • Oracle Linux: version 6 only; version 7 only
  • Oracle Secure Backup: up to and including 12.1.0.1.0
  • Oracle Solaris: version 11.2 only
  • PHP PHP: before 5.5.24 (fixed in 5.5.24); from 5.6.0, before 5.6.8 (fixed in 5.6.8)

Published 2015-03-30. Last modified 2026-06-17.