Description
The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.
Remediation
References
Related Vulnerabilities
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-4321)
OpenSSL Other Vulnerability (CVE-2005-2969)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2200)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-30152)
WordPress Plugin Hotjar Connecticator Cross-Site Scripting (1.1.1)