Description
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
Remediation
References
Related Vulnerabilities
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.1)
Magento Deserialization of Untrusted Data Vulnerability (CVE-2019-8141)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2402)
WordPress Plugin Asgaros Forum Cross-Site Scripting (1.0.7)
WordPress Plugin Peter's Math Anti-Spam Audio CAPTCHA Security Bypass (0.1.6)