CVE-2016-9934NULL Pointer Dereference in PHP

Severity
7.5HIGHNVD
OSV9.8
EPSS
11.6%
top 6.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateMay 14

Description

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Ubuntuphp5/php5< 5.5.9+dfsg-1ubuntu4.21
NVDphp/php5.6.27+13
Appleapple/macos_sierra10.12.3

🔴Vulnerability Details

3
GHSA
GHSA-9r3m-57qh-73fc: ext/wddx/wddx2022-05-14
OSV
php5 vulnerabilities2017-02-14
OSV
CVE-2016-9934: ext/wddx/wddx2017-01-04

📋Vendor Advisories

3
Ubuntu
PHP vulnerabilities2017-02-14
Apple
CVE-2016-9934: macOS Sierra 10.12.32017-01-23
Red Hat
php: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow2015-12-08

💬Community

2
Bugzilla
CVE-2016-9933 CVE-2016-9934 CVE-2016-9935 CVE-2016-9936 php: various flaws [fedora-all]2016-12-14
Bugzilla
CVE-2016-9934 php: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow2016-12-14
CVE-2016-9934 — NULL Pointer Dereference in PHP | cvebase