Description
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
Remediation
References
Related Vulnerabilities
WordPress 4.1.x Same Origin Method Execution (SOME) Vulnerability (4.1 - 4.1.10)
WordPress Plugin WPCS-WordPress Currency Switcher Cross-Site Request Forgery (1.1.6)
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.7)
WordPress Plugin The Events Calendar Countdown Addon Security Bypass (1.3.1)