Description
The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server Integer Overflow or Wraparound Vulnerability (CVE-2022-22721)
WordPress Resource Management Errors Vulnerability (CVE-2014-5265)
Drupal Other Vulnerability (CVE-2007-4063)
WordPress Plugin Slideshow Multiple Cross-Site Scripting Vulnerabilities (2.1.14)
WordPress Plugin Import and export users and customers Cross-Site Scripting (1.14.1.2)