Description
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call.
Remediation
References
Related Vulnerabilities
Moodle Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-9187)
MySQL CVE-2018-2787 Vulnerability (CVE-2018-2787)
PHP Numeric Errors Vulnerability (CVE-2007-1001)
Apache HTTP Server Other Vulnerability (CVE-2002-0843)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.38)