Description
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
Remediation
References
Related Vulnerabilities
WordPress Plugin Mimetic Books Cross-Site Scripting (0.2.13)
WordPress Plugin MailPoet Newsletters (Previous) Cross-Site Scripting (2.6.19)
WordPress Plugin Fitness Trainer-Training Membership Cross-Site Scripting (1.0.8)
Mibew Messenger Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0829)