Description
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2012-2336)
PHP Other Vulnerability (CVE-2015-6832)
OpenSSL Resource Management Errors Vulnerability (CVE-2016-2109)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (18.3)
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Cross-Site Scripting (6.0.6)