Fedora Account System
Red Hat Associate
Red Hat Customer
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
MITRE description: The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.