Critical severity9.8NVD Advisory· Published Mar 31, 2016· Updated May 6, 2026
CVE-2016-3141
CVE-2016-3141
Description
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
Affected products
21cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.5.32
- cpe:2.3:a:php:php:5.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.17:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.18:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- lists.apple.com/archives/security-announce/2016/May/msg00004.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00052.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00056.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00057.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00058.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-2750.htmlnvd
- www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlnvd
- www.securityfocus.com/bid/84271nvd
- www.securitytracker.com/id/1035255nvd
- www.ubuntu.com/usn/USN-2952-1nvd
- www.ubuntu.com/usn/USN-2952-2nvd
- bugs.php.net/bug.phpnvd
- php.net/ChangeLog-5.phpnvd
- support.apple.com/HT206567nvd
News mentions
0No linked articles in our index yet.