PT-2016-3406 · Php+4 · Php+4

Hans Jerry Illikainen

·

Published

2016-07-22

·

Updated

2023-02-12

·

CVE-2016-5399

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.38 PHP versions 5.6.x prior to 5.6.24 PHP versions 7.x prior to 7.0.9
Description The issue is related to the bzread function in the PHP interpreter, which is vulnerable to a buffer overflow in memory. This can be exploited by a remote attacker using a specially crafted .bz2 archive, potentially leading to a denial of service or the execution of arbitrary code.
Recommendations For PHP versions prior to 5.5.38, update to version 5.5.38 or later. For PHP versions 5.6.x prior to 5.6.24, update to version 5.6.24 or later. For PHP versions 7.x prior to 7.0.9, update to version 7.0.9 or later.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-02544
CESA-2016_2598
CVE-2016-5399
DLA-628-1
DSA-3631-1
OPENSUSE-SU-2016_2451-1
RHSA-2016:2598
RHSA-2016:2750
RHSA-2016_2598
SUSE-SU-2016:2080-1
SUSE-SU-2016:2210-1
SUSE-SU-2016:2328-1
SUSE-SU-2016:2408-1
SUSE-SU-2016:2460-1
SUSE-SU-2016:2460-2
USN-3045-1

Affected Products

Centos
Php
Red Hat
Suse
Ubuntu