#VU16137 Heap-based buffer overflow in PHP - CVE-2016-7134
Published: November 27, 2018
PHP
PHP Group
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in ext/curl/interface.c in PHP 7.x before 7.0.10. A remote attacker can use a long string that is mishandled in a curl_escape call. to trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- http://openwall.com/lists/oss-security/2016/09/02/9
- http://www.php.net/ChangeLog-7.php
- http://www.securityfocus.com/bid/92766
- http://www.securitytracker.com/id/1036680
- https://bugs.php.net/bug.php?id=72674
- https://github.com/php/php-src/commit/72dbb7f416160f490c4e9987040989a10ad431c7?w=1
- https://security.gentoo.org/glsa/201611-22