Title: PHP wddx Extension Unspecified Information Disclosure
Info
Disclosure
Feb 09, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
PHP contains a flaw that may allow a context-dependent attacker to gain access to privileged information. The issue is due to the WDDX deserializer in the wddx extension not properly initializing the key_length variable for numerical keys. This may allow an attacker to read arbitrary parts of the stack memory via a crafted wddxPacket alement.
Classification
Location:
Context Dependent
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Disclosure:
Vendor Verified
Solution
Upgrade to version 4.4.5, 5.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.