CVE-2016-4070
Severity CVSS v4.0:
Pending analysis
Type:
CWE-189
Numeric Errors
Publication date:
20/05/2016
Last modified:
12/04/2025
Description
Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode function. NOTE: the vendor says "Not sure if this qualifies as security issue (probably not).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | 5.5.33 (including) | |
| cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.html
- http://rhn.redhat.com/errata/RHSA-2016-2750.html
- http://www.debian.org/security/2016/dsa-3560
- http://www.openwall.com/lists/oss-security/2016/04/24/1
- http://www.php.net/ChangeLog-5.php
- http://www.php.net/ChangeLog-7.php
- http://www.securityfocus.com/bid/85801
- http://www.ubuntu.com/usn/USN-2952-1
- http://www.ubuntu.com/usn/USN-2952-2
- https://bugs.php.net/bug.php?id=71798
- https://git.php.net/?p=php-src.git%3Ba%3Dcommit%3Bh%3D95433e8e339dbb6b5d5541473c1661db6ba2c451
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://support.apple.com/HT206567
- http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.html
- http://rhn.redhat.com/errata/RHSA-2016-2750.html
- http://www.debian.org/security/2016/dsa-3560
- http://www.openwall.com/lists/oss-security/2016/04/24/1
- http://www.php.net/ChangeLog-5.php
- http://www.php.net/ChangeLog-7.php
- http://www.securityfocus.com/bid/85801
- http://www.ubuntu.com/usn/USN-2952-1
- http://www.ubuntu.com/usn/USN-2952-2
- https://bugs.php.net/bug.php?id=71798
- https://git.php.net/?p=php-src.git%3Ba%3Dcommit%3Bh%3D95433e8e339dbb6b5d5541473c1661db6ba2c451
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://support.apple.com/HT206567



