Description
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
Remediation
References
Related Vulnerabilities
IBMHttpServer Other Vulnerability (CVE-2000-1168)
MySQL CVE-2016-0646 Vulnerability (CVE-2016-0646)
Oracle Database Server CVE-2009-0997 Vulnerability (CVE-2009-0997)
MongoDb Improper Encoding or Escaping of Output Vulnerability (CVE-2021-20333)
PostgreSQL Out-of-bounds Write Vulnerability (CVE-2015-0242)