{"id":"CVE-2016-10162","details":"The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.","modified":"2026-08-07T14:31:33.172547Z","published":"2017-01-24T21:59:00.307Z","related":["SUSE-SU-2017:0534-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/95668"},{"type":"WEB","url":"http://www.securitytracker.com/id/1037659"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-7.php"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73831"},{"type":"FIX","url":"https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"last_affected":"0221e9f827632942225586687a33cfd554860d5e"},{"fixed":"8d2539fa0faf3f63e1d1e7635347c5b9e777d47b"}],"database_specific":{"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.1.0"},{"last_affected":"7.1.0"}],"source":["CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*"]}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.11","7.0.12","7.0.13","7.0.14","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0.9","7.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10162.json","vanir_signatures_modified":"2026-08-07T14:31:33Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b","target":{"file":"ext/wddx/wddx.c","function":"php_wddx_pop_element"},"deprecated":false,"digest":{"function_hash":"52155622896470577037637253148168673813","length":3459},"id":"CVE-2016-10162-7e6f783f"},{"target":{"file":"ext/wddx/wddx.c"},"deprecated":false,"digest":{"line_hashes":["1620018376375737470682412624291272126","75860513361137437258853901596366910981","157230416959749458864575248492656206639","22900006191810578093947685641424325424","211965975932477732014969696767726657886","185584415137237897076600071513667432310","54977184172081566024379389457367593029","68290105138880958354684018990467199094","256219010245046166543126998915680796348","299104130098631164721253267590865955096","194343109413117409065661647869676528118","190131494537551333221630627471275714625","149280764790086418306903979506717890826","7347544924061215204222971421391995387","90515752481232727115992206495968917950"],"threshold":0.9},"id":"CVE-2016-10162-920d982d","signature_type":"Line","signature_version":"v1","source":"https://github.com/php/php-src/commit/8d2539fa0faf3f63e1d1e7635347c5b9e777d47b"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}