Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5399

Опубликовано: 21 апр. 2017
Источник: debian
EPSS Средний

Описание

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.9-1package
php5fixed5.6.24+dfsg-1package

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=72613

  • Partial fixes in 7.0.9, 5.6.24, 5.5.38

  • CVE is assigned for the issue in PHP in adequate error handling in the

  • bzread() function. Disputed by PHP upstream, which considers that the

  • underlying bzip2 library is at fault.

EPSS

Процентиль: 95%
0.18733
Средний

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 8.1
redhat
почти 9 лет назад

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 7.8
nvd
около 8 лет назад

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 7.8
github
около 3 лет назад

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 8.8
fstec
около 8 лет назад

Уязвимость функции bzread (ext/bz2/bz2.c) интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 95%
0.18733
Средний