Back
CVE-2016-7413
CRITICAL
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document that lacks an end-tag for a recordset field element, leading to mishandling in a wddx_deserialize call.
Published: Sep 17, 2016
Modified: Jun 17, 2026
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (12)
| Vendor | Product | Version |
|---|---|---|
| php | php | * |
| php | php | 7.0.0 |
| php | php | 7.0.1 |
| php | php | 7.0.2 |
| php | php | 7.0.3 |
| php | php | 7.0.4 |
| php | php | 7.0.5 |
| php | php | 7.0.6 |
| php | php | 7.0.7 |
| php | php | 7.0.8 |
| php | php | 7.0.9 |
| php | php | 7.0.10 |
GitHub Security Advisory GHSA-9m4c-2m8h-f93q
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before...
References (20)
- http://www.openwall.com/lists/oss-security/2016/09/15/10 Mailing List
- http://www.php.net/ChangeLog-5.php Release Notes
- http://www.php.net/ChangeLog-7.php Release Notes
- http://www.securityfocus.com/bid/93006
- http://www.securitytracker.com/id/1036836
- https://access.redhat.com/errata/RHSA-2018:1296
- https://bugs.php.net/bug.php?id=72860 Exploit, Issue Tracking
- https://github.com/php/php-src/commit/b88393f08a558eec14964a55d3c680fe67407712?w=1 Issue Tracking, Patch
- https://security.gentoo.org/glsa/201611-22
- https://www.tenable.com/security/tns-2016-19
- http://www.openwall.com/lists/oss-security/2016/09/15/10 Mailing List
- http://www.php.net/ChangeLog-5.php Release Notes
- http://www.php.net/ChangeLog-7.php Release Notes
- http://www.securityfocus.com/bid/93006
- http://www.securitytracker.com/id/1036836
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
6.65%
Top 7% most likely to be exploited
Threat Score
41.2 / 100
Data Sources
NVD
EPSS
GitHub