Description
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty boolean element in a wddxPacket XML document.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3390)
Telerik Web UI Inadequate Encryption Strength Vulnerability (CVE-2017-11317)
WordPress CVE-2016-5836 Vulnerability (CVE-2016-5836)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-46147)
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2023-26116)