CVE-2016-7129

critical
Published 2016-09-12 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, as demonstrated by a wddx_deserialize call that mishandles a dateTime element in a wddxPacket XML document.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-7129.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/php/php-src/commit/426aeb2808955ee3d3f52e0cfb102834cdb836a5?w=1

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.php.net/ChangeLog-7.php

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.php.net/ChangeLog-5.php

OS impact

OSVersionStatusFixed in
suse slesaffected

Application impact

VendorProductVersionsFixed
php phpphp7.0.0
php phpphp7.0.1
php phpphp7.0.2
php phpphp7.0.3
php phpphp7.0.4
php phpphp7.0.5
php phpphp7.0.6
php phpphp7.0.7
php phpphp7.0.8
php phpphp7.0.9
php phpphp{"endIncluding":"5.6.24"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.