PT-2016-1127 · Php · Php

Publicado

2016-01-19

·

Atualizado

2016-12-07

·

CVE-2016-1904

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.0.2
Description The issue is caused by multiple integer overflows in the ext/standard/exec.c file of PHP, specifically in the php escape shell cmd and php escape shell arg functions. This can lead to a heap-based buffer overflow when a long string is provided to these functions, potentially allowing remote attackers to cause a denial of service or have other unspecified impacts.
Recommendations For PHP versions prior to 7.0.2, update to version 7.0.2 or later to resolve the issue. As a temporary workaround, consider restricting the input length to the php escape shell cmd and php escape shell arg functions to prevent exploitation.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00386
CVE-2016-1904

Produtos afetados

Php