CVE Database
/

CVE-2016-5772

Back to search

CVE-2016-5772

Published: Aug 7, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2016-09-20
vendor-advisory
x_refsource_APPLE
openSUSE-SU-2016:1761
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2016:1922
vendor-advisory
x_refsource_SUSE
RHSA-2016:2750
vendor-advisory
x_refsource_REDHAT
DSA-3618
vendor-advisory
x_refsource_DEBIAN
91398
vdb-entry
x_refsource_BID
SUSE-SU-2016:2013
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now