Description
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Remediation
References
Related Vulnerabilities
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-20330)
WordPress Plugin NextGEN Gallery-WordPress Gallery PHP Object Injection (3.1.5)
MediaWiki Insecure Storage of Sensitive Information Vulnerability (CVE-2021-36127)
Python Improper Input Validation Vulnerability (CVE-2023-27043)
WordPress Plugin Really Simple Gallery Multiple Vulnerabilities (1.4)