The phpwddxpopelement function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddxdeserialize call.
[
{
"deprecated": false,
"source": "https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b",
"id": "CVE-2016-10162-7e6f783f",
"digest": {
"function_hash": "52155622896470577037637253148168673813",
"length": 3459.0
},
"target": {
"function": "php_wddx_pop_element",
"file": "ext/wddx/wddx.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b",
"id": "CVE-2016-10162-920d982d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"1620018376375737470682412624291272126",
"75860513361137437258853901596366910981",
"157230416959749458864575248492656206639",
"22900006191810578093947685641424325424",
"211965975932477732014969696767726657886",
"185584415137237897076600071513667432310",
"54977184172081566024379389457367593029",
"68290105138880958354684018990467199094",
"256219010245046166543126998915680796348",
"299104130098631164721253267590865955096",
"194343109413117409065661647869676528118",
"190131494537551333221630627471275714625",
"149280764790086418306903979506717890826",
"7347544924061215204222971421391995387",
"90515752481232727115992206495968917950"
]
},
"target": {
"file": "ext/wddx/wddx.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]