The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 7.0.0 (including) | 7.0.0 (including) |
Php | Php | 7.0.1 (including) | 7.0.1 (including) |
Php | Php | 7.0.2 (including) | 7.0.2 (including) |
Php | Php | 7.0.3 (including) | 7.0.3 (including) |
Php | Php | 7.0.4 (including) | 7.0.4 (including) |
Php | Php | 7.0.5 (including) | 7.0.5 (including) |
Php | Php | 7.0.6 (including) | 7.0.6 (including) |
Php | Php | 7.0.7 (including) | 7.0.7 (including) |
Php | Php | 7.0.8 (including) | 7.0.8 (including) |
Php | Php | 7.0.9 (including) | 7.0.9 (including) |
Php | Php | 7.0.10 (including) | 7.0.10 (including) |
Php | Php | 7.0.11 (including) | 7.0.11 (including) |
Php | Php | 7.0.12 (including) | 7.0.12 (including) |
Php | Php | 7.0.13 (including) | 7.0.13 (including) |
Php | Php | 7.0.14 (including) | 7.0.14 (including) |
Php | Php | 7.1.0 (including) | 7.1.0 (including) |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php70-php-0:7.0.27-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php70-php-0:7.0.27-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Php7.0 | Ubuntu | devel | * |
Php7.0 | Ubuntu | upstream | * |
Php7.0 | Ubuntu | xenial | * |
Php7.0 | Ubuntu | yakkety | * |