PT-2016-2089 · Php · Php

Manhluat

·

Publicado

2016-05-21

·

Atualizado

2022-07-20

·

CVE-2016-4345

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.0.4
Description The issue is related to an integer overflow in the php filter encode url function, which can cause a heap-based buffer overflow. This can lead to a denial of service or possibly have other unspecified impacts when a remote attacker sends a long string.
Recommendations For PHP versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the input length to the php filter encode url function to minimize the risk of exploitation.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01441
CVE-2016-4345

Produtos afetados

Php