Back

CVE-2016-5772

CRITICAL

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.

Published: Aug 7, 2016 Modified: Jun 17, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
php php * < 5.5.37
php php * ≥ 5.6.0 < 5.6.23
php php * ≥ 7.0.0 < 7.0.8
suse linux_enterprise_debuginfo 11
opensuse leap 42.1
opensuse opensuse 13.2
suse linux_enterprise_server 11
suse linux_enterprise_software_development_kit 11
debian debian_linux 8.0

GitHub Security Advisory GHSA-v2qq-h2h4-pjqv

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 9.67%

Top 5% most likely to be exploited

Threat Score 42.1 / 100

Data Sources

NVD EPSS GitHub