Description
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Limit Login Attempts SQL Injection (2.0.0)
WordPress Plugin Analyticator PHP Object Injection (6.5.5)
Oracle JRE CVE-2013-1557 Vulnerability (CVE-2013-1557)
WordPress Plugin Realtyna Organic IDX + WPL Real Estate Arbitrary File Upload (4.14.13)
WebLogic Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2018-11040)