Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7133

Опубликовано: 12 сент. 2016
Источник: debian
EPSS Низкий

Описание

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.10-1package
php5not-affectedpackage

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=72742

  • Fixed in 7.0.10

  • https://www.openwall.com/lists/oss-security/2016/09/02/5

  • https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911?w=1

EPSS

Процентиль: 67%
0.00544
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 9 лет назад

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

CVSS3: 7.5
redhat
почти 9 лет назад

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

CVSS3: 8.1
nvd
почти 9 лет назад

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

CVSS3: 8.1
github
больше 3 лет назад

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

suse-cvrf
почти 9 лет назад

Security update for php7

EPSS

Процентиль: 67%
0.00544
Низкий