go to bug id or search bugs for
If wddx_serialize_value is called on a SimpleXMLElement object that has at least one child, the PHP script enters an infinite loop consuming full CPU and allocating memory until the memory size limit is reached, after which the script dies.
$xml = new SimpleXMLElement('<data></data>');
echo wddx_serialize_value($xml, 'Variables');
echo 'hello world';
To see the WDDX output and 'hello world' :)
Potential DoS against web server and this log entry:
[Sun Aug 24 06:44:19 2008] [error] [client 127.0.0.1] PHP Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 133955606 bytes) in /usr/home/aragon/dev/admin.infinite/test.php on line 5
Add a Patch
Add a Pull Request
Please try using this CVS snapshot:
For Windows (zip):
For Windows (installer):
No feedback was provided for this bug for over a week, so it is
being suspended automatically. If you are able to provide the
information that was originally requested, please do so and change
the status of the bug back to "Open".
I can reproduce using 5.3CVS.
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
Thank you for the report, and for helping us make PHP better.