Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP WDDX扩展缓冲区溢出漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。WDDX是其中的一个基于XML的Web分布式数据交换扩展模块。 PHP 5.5.32及之前版本和5.6.19之前5.6.x版本的WDDX扩展中的wddx.c文件存在释放后重用漏洞。远程攻击者可通过触发包含特制var元素的XML数据上的wddx_deserialize调用,利用该漏洞造成拒绝服务(内存损坏和应用程序崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A