CVE-2013-4113: PHP
Medium severity, CVSS 6.8. EPSS: 5.2% chance of exploitation in the next 30 days.
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Affected products
- PHP PHP: from 5.3.0, before 5.3.27 (fixed in 5.3.27); from 5.4.0, before 5.4.18 (fixed in 5.4.18)
Published 2013-07-13. Last modified 2026-06-16.