CVE-2016-4539 PUBLISHED

The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other impact via crafted XML data in the second argument, leading to a parser level of zero.

EPSS 4.51% · 89.0th percentile

Risk Scores

EPSS Score
4.51%
89.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSphp50, 5.5.3+dfsg-1ubuntu2, 5.5.3+dfsg-1ubuntu3
Ubuntu:16.04:LTSphp7.00, 7.0.1-5, 7.0.1-6

Timeline

References

Open in Interactive Console →