PT-2016-2088 · Php+1 · Php+1

Manhluat

·

Published

2016-05-21

·

Updated

2022-07-20

·

CVE-2016-4346

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.0.4
Description The issue is related to an integer overflow in the str pad function, which can cause a heap-based buffer overflow when a long string is used. This can allow a remote attacker to cause a denial of service or possibly have other unspecified impacts.
Recommendations For PHP versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the str pad function with long strings until a patch is available.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01440
CVE-2016-4346
SUSE-SU-2016:1504-1
SUSE-SU-2016:1581-1
SUSE-SU-2016:1638-1

Affected Products

Php
Suse