Description
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.
Remediation
References
Related Vulnerabilities
Chamilo Other Vulnerability (CVE-2023-34958)
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3722)
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.6)
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.2)
WordPress Plugin WP OAuth Server (OAuth Authentication) Security Bypass (3.1.4)