Описание
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | php | Will not fix | ||
Red Hat Enterprise Linux 5 | php53 | Will not fix | ||
Red Hat Enterprise Linux 6 | php | Will not fix | ||
Red Hat Enterprise Linux 7 | php | Will not fix | ||
Red Hat Software Collections | php54-php | Will not fix | ||
Red Hat Software Collections | php55-php | Will not fix | ||
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56 | Fixed | RHSA-2016:2750 | 15.11.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php | Fixed | RHSA-2016:2750 | 15.11.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-pear | Fixed | RHSA-2016:2750 | 15.11.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56 | Fixed | RHSA-2016:2750 | 15.11.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remo ...
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
Уязвимость компонента ext/wddx/wddx.c интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3
4.3 Medium
CVSS2