Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19292
HistoryMay 16, 2019 - 2:59 a.m.

Use After Free

2019-05-1602:59:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.017 Low

EPSS

Percentile

87.8%

PHP is vulnerable to use after free vulnerability. The vulnerability exists in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP. Remote attackers could cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document that lacks an end-tag for a recordset field element, leading to mishandling in a wddx_deserialize call.