ext/xml/xml.c in PHP prior to 5.3.27 does not properly consider parsing depth, which allows remote malicious users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php php |