Description
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
Remediation
References
Related Vulnerabilities
WordPress Plugin Visitor Traffic Real Time Statistics Cross-Site Request Forgery (2.12)
WebLogic Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2018-11040)
Apache Tomcat Insufficient Verification of Data Authenticity Vulnerability (CVE-2017-7674)
SharePoint Improper Certificate Validation Vulnerability (CVE-2019-1006)