Description
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
Remediation
References
Related Vulnerabilities
Drupal Core 4.6.x Multiple Vulnerabilities (4.6.0 - 4.6.3)
WordPress Plugin FourSquare Checkins Cross-Site Request Forgery (1.2)
WordPress Plugin Subscribe2 Multiple Cross-Site Scripting Vulnerabilities (8.1)
WordPress Plugin Newsletter Manager Multiple Cross-Site Scripting Vulnerabilities (1.0.1)
Oracle Database Server CVE-2012-0511 Vulnerability (CVE-2012-0511)