Description
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stylish Price List Security Bypass (6.8.14)
Squid Improper Input Validation Vulnerability (CVE-2016-2571)
WordPress Plugin Crisp Live Chat Cross-Site Request Forgery (0.31)
Drupal Core 8.9.0 Cross-Site Request Forgery (8.9.0)
Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2024-32976)