CVE-2016-3141 PUBLISHED

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

EPSS 72.28% · 98.7th percentile

Risk Scores

EPSS Score
72.28%
98.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSphp50, 5.5.3+dfsg-1ubuntu2, 5.5.3+dfsg-1ubuntu3

Timeline

References

Open in Interactive Console →