Description
ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.
Remediation
References
Related Vulnerabilities
PHP Out-of-bounds Write Vulnerability (CVE-2016-5399)
Oracle Database Server CVE-2010-2389 Vulnerability (CVE-2010-2389)
WordPress Plugin Download Monitor Cross-Site Scripting (1.7.0)
WordPress Plugin Active Directory Integration SQL Injection (1.1.8)
WordPress Plugin Indexisto WordPress Site Search Cross-Site Scripting (1.0.5)