Description
ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.
Remediation
References
Related Vulnerabilities
Moodle Improper Privilege Management Vulnerability (CVE-2019-3849)
MySQL CVE-2020-14623 Vulnerability (CVE-2020-14623)
WebLogic CVE-2020-14638 Vulnerability (CVE-2020-14638)
Apache Tomcat version older than 6.0.35
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)