CVE

Id
94238  
CVE No.
CVE-2016-7418  
Status
Candidate  
Description
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.  
Phase
Assigned (20160909)  
Votes
None (candidate not yet proposed)  
Comments