Back

CRITICAL

php: Use after free in WDDX Deserialize when processing XML data

Published Mar 31, 2016

Description

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Mar 31, 2016
Updated Aug 5, 2024
Reserved Mar 13, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 14, 2016