{"id":"CVE-2016-7418","details":"The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.","modified":"2026-08-07T14:48:19.535263Z","published":"2016-09-17T21:59:10.590Z","related":["SUSE-SU-2016:2459-1","SUSE-SU-2016:2460-1","SUSE-SU-2016:2460-2","SUSE-SU-2016:2461-1","SUSE-SU-2016:2477-1","SUSE-SU-2016:2477-2"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/93011"},{"type":"WEB","url":"http://www.securitytracker.com/id/1036836"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2016-19"},{"type":"ADVISORY","url":"http://www.php.net/ChangeLog-5.php"},{"type":"ADVISORY","url":"http://www.php.net/ChangeLog-7.php"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201611-22"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73065"},{"type":"FIX","url":"https://github.com/php/php-src/commit/c4cca4c20e75359c9a13a1f9a36cb7b4e9601d29?w=1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/09/15/10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"e37064dae4a80c70405899bb591969bbe6aad9a8"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"last_affected":"da12ca9c1ed03084e6803f5e81e46f2e0a80460a"},{"fixed":"c4cca4c20e75359c9a13a1f9a36cb7b4e9601d29"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.6.25"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"}]}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0.9","php-5.6.25","php-7.0.10","php-5.6.25RC1","php-7.0.10RC1","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7418.json","vanir_signatures_modified":"2026-08-07T14:48:19Z","vanir_signatures":[{"source":"https://github.com/php/php-src/commit/c4cca4c20e75359c9a13a1f9a36cb7b4e9601d29","target":{"file":"ext/wddx/wddx.c","function":"php_wddx_push_element"},"deprecated":false,"digest":{"function_hash":"301755387465239169747237975694531964431","length":4854},"id":"CVE-2016-7418-760e79e7","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["308694738579821330575113088819953920852","84685106283968628504680174502681186750","211346454573652685734979468850567577816","18489613605778186720515946013870429298","249598479934599620074032434067904094637","15983837247249289812712296581946220790","324664599945258097417736163646327943350","136356109348485930596258890158835077254","27052967596267270576444515664299000484","204386543369611475760358364132751115204","210067127343357516321561959327529389397","336428203481456014216272231594019601213","218660437309276509347849730681931299111","47587827024300610377702192824979977266","108112416631527217460140097544647415290","174749150332282443750440209917291064153","58039656399573981131841824752074006686","193234765473047900801339128086207549659","332613737563562772784506183104791857778","282220600908517069566001490611677413494","144261495474165999922135191429869395205","119831470993581856570386852775908731078","4293155750088484306679532266909695460","171322702806979196618087965127779297756","91635138978443424222239518240134551202","291825211060746831943962194003986966104","174062326053673189029702070890453612045","284827188498645453215671116196214305846","23465117317755467644845650613445216244","222850536836707307193417947187898618565","217815023334364138222218364120377904306","255372112077290822634886472988781142970","55128966905359705429461440335881369597","216781671013480326658757297888782661620","99412707763629256313032685967627343200","42672048477788047917688512924494305538"],"threshold":0.9},"id":"CVE-2016-7418-9c7c3b2c","signature_type":"Line","signature_version":"v1","source":"https://github.com/php/php-src/commit/c4cca4c20e75359c9a13a1f9a36cb7b4e9601d29","target":{"file":"ext/wddx/wddx.c"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}