CVE-2013-4113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/07/2013
Last modified:
11/04/2025

Description

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.27 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.18 (excluding)


References to Advisories, Solutions, and Tools