CVE-2013-4113: PHP

Medium severity, CVSS 6.8. EPSS: 5.2% chance of exploitation in the next 30 days.

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Affected products

  • PHP PHP: from 5.3.0, before 5.3.27 (fixed in 5.3.27); from 5.4.0, before 5.4.18 (fixed in 5.4.18)

Published 2013-07-13. Last modified 2026-06-16.