Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7134

Опубликовано: 12 сент. 2016
Источник: debian
EPSS Низкий

Описание

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.10-1package
php5not-affectedpackage

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=72674

  • Fixed in 7.0.10

  • https://www.openwall.com/lists/oss-security/2016/09/02/5

  • https://github.com/php/php-src/commit/72dbb7f416160f490c4e9987040989a10ad431c7?w=1

EPSS

Процентиль: 66%
0.00519
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

CVSS3: 7.5
redhat
около 9 лет назад

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

CVSS3: 9.8
nvd
около 9 лет назад

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

CVSS3: 9.8
github
больше 3 лет назад

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

suse-cvrf
около 9 лет назад

Security update for php5

EPSS

Процентиль: 66%
0.00519
Низкий