PT-2016-3406 · Php+4 · Php+4

Hans Jerry Illikainen

·

Publicado

2016-07-22

·

Atualizado

2023-02-12

·

CVE-2016-5399

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.38 PHP versions 5.6.x prior to 5.6.24 PHP versions 7.x prior to 7.0.9
Description The issue is related to the bzread function in the PHP interpreter, which is vulnerable to a buffer overflow in memory. This can be exploited by a remote attacker using a specially crafted .bz2 archive, potentially leading to a denial of service or the execution of arbitrary code.
Recommendations For PHP versions prior to 5.5.38, update to version 5.5.38 or later. For PHP versions 5.6.x prior to 5.6.24, update to version 5.6.24 or later. For PHP versions 7.x prior to 7.0.9, update to version 7.0.9 or later.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02544
CESA-2016_2598
CVE-2016-5399
DLA-628-1
DSA-3631-1
OPENSUSE-SU-2016_2451-1
RHSA-2016:2598
RHSA-2016:2750
RHSA-2016_2598
SUSE-SU-2016:2080-1
SUSE-SU-2016:2210-1
SUSE-SU-2016:2328-1
SUSE-SU-2016:2408-1
SUSE-SU-2016:2460-1
SUSE-SU-2016:2460-2
USN-3045-1

Produtos afetados

Centos
Php
Red Hat
Suse
Ubuntu