CVE-2017-11143

HIGH

Php < 5.6.30 - Insecure Deserialization

Title source: rule

Description

In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.

Scores

CVSS v3 7.5
EPSS 0.1186
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-502 CWE-416
Status draft

Affected Products (1)

php/php < 5.6.30

Timeline

Published Jul 10, 2017
Tracked Since Feb 18, 2026