CVE-2011-1148
Use-after-free vulnerability in the substr_replace function in PHP 5.3.6 and earlier allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by using the same variable for multiple arguments.
Date published : 2011-03-18
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html