CVE-2013-4113

medium
Published 2013-07-13 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.php.net/bug.php?id=65236

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://php.net/archive/2013.php#id2013-07-11-1

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://php.net/ChangeLog-5.php

Application impact

VendorProductVersionsFixed
php phpphp{"startIncluding":"5.3.0","endExcluding":"5.3.27"}5.3.27

References

CWEs

CWE-787

Verify integrity in audit chain (admin only). AS-IS.