Description
The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRFUNC and (b) GLOB_APPEND.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-UserOnline Cross-Site Scripting (2.88.0)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2018-1302)
WordPress Plugin GistPress Cross-Site Scripting (3.0.1)
WordPress Plugin Easy Forms for Mailchimp Unspecified Vulnerability (6.6.2)
WordPress Plugin BestSmallShopLite Cross-Site Scripting (1.0.1)