Return to the home page
New Vulnerability in PHP's extract() Function Allows Arbitrary Code Execution

New Vulnerability in PHP's extract() Function Allows Arbitrary Code Execution

VulnerabilitiesCode ExecutionPHPCybersecurity

A new report describes a vulnerability in the extract() function of PHP that allows attackers to trigger a double-free. This vulnerability can then enable the execution of arbitrary code (native code).