Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7416

Опубликовано: 03 сент. 2016
Источник: redhat
CVSS3: 7.8
CVSS2: 5.1
EPSS Низкий

Описание

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 6phpWill not fix
Red Hat Enterprise Linux 7phpWill not fix
Red Hat Software Collectionsphp54-phpWill not fix
Red Hat Software Collectionsphp55-phpWill not fix
Red Hat Software Collectionsrh-php56-phpWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-php70-phpFixedRHSA-2018:129603.05.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-php70-phpFixedRHSA-2018:129603.05.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-php70-phpFixedRHSA-2018:129603.05.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1377340php: Stack based buffer overflow in msgfmt_format_message

EPSS

Процентиль: 89%
0.05085
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

CVSS3: 7.5
nvd
почти 9 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

CVSS3: 7.5
debian
почти 9 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x bef ...

CVSS3: 7.5
github
около 3 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

CVSS3: 7.5
fstec
почти 9 лет назад

Уязвимость компонента ext/intl/msgformat/msgformat_format.c интерпретатора языка программирования PHP , позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 89%
0.05085
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2