Description
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
Remediation
References
Related Vulnerabilities
WordPress Plugin Rich Table of Contents Cross-Site Scripting (1.3.7)
WordPress Plugin Plainview Activity Monitor Remote Command Execution (20161228)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3545)
WordPress Plugin Ultimate Addons for Beaver Builder Cross-Site Scripting (1.24.3)