PT-2016-2089 · Php · Php

Manhluat

·

Published

2016-05-21

·

Updated

2022-07-20

·

CVE-2016-4345

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.0.4
Description The issue is related to an integer overflow in the php filter encode url function, which can cause a heap-based buffer overflow. This can lead to a denial of service or possibly have other unspecified impacts when a remote attacker sends a long string.
Recommendations For PHP versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the input length to the php filter encode url function to minimize the risk of exploitation.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01441
CVE-2016-4345

Affected Products

Php