Description
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.
Remediation
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5624)
Apache 2.x version older than 2.0.46
WordPress Plugin WordPress Ultra Simple Paypal Shopping Cart Cross-Site Request Forgery (4.4)
WordPress Plugin Login Widget With Shortcode Cross-Site Request Forgery (3.1.1)
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-6931)